Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Exploit Developer Tool to Conceal Backdoor

Iranian Hackers Exploit Developer Tool to Conceal Backdoor

Posted on August 26, 2026 By CWS

An Iranian-linked hacker group has been leveraging a legitimate developer tool to obscure a backdoor known as Dindoor within Windows operating systems. This tactic, which utilizes the Deno JavaScript and TypeScript runtime, allows the malware to operate under the guise of standard software processes.

Concealed Operations in Various Sectors

Dindoor has been deployed as a subsequent payload in targeted spearphishing attacks. Its presence has been detected in U.S. software and banking firms, as well as a Canadian non-profit, indicating its broad reach across multiple industries. The cybersecurity firm Binary Defense has been tracking this backdoor since early 2026, attributing the activity to the Iranian threat group known as MuddyWater.

According to a report shared with Cyber Security News, Dindoor’s approach combines a signed runtime and Base64 encoding, effectively evading traditional analysis. This method doesn’t rely on a single suspicious executable, but rather integrates familiar Windows utilities and a legitimate runtime to create a seemingly harmless delivery chain.

Detailed Infection Process

The infection process begins with a phishing attack that installs a loader on the target device. If the Deno runtime is not present, the malware uses the curl utility to download it, subsequently launching it with a Base64-encoded argument containing the Dindoor code. This installation, though not inherently suspicious, warrants scrutiny on non-developer systems, especially after phishing or unusual script activities.

The initial script executed by Dindoor gathers data from the compromised host and communicates with a remote server to compile a secondary payload. This payload retrieves and executes a third stage, creating a complex chain that complicates investigation and allows operators to modify components as needed.

Countermeasures and Detection Strategies

To establish persistence, Dindoor uses a Windows Run registry entry to launch a VBScript with wscript upon user login. This multi-stage tactic resembles previous strategies used by MuddyWater, designed to minimize visibility and maintain access.

Detection efforts must focus on behavior rather than static indicators. High-value signs include the execution of Deno with an unusually long encoded argument, unexpected curl activity, and registry entries pointing wscript to scripts in the AppData Local directory. Additionally, PowerShell queries for graphics adapters, indicative of virtual environments, should prompt further investigation.

Organizations can reduce their exposure by monitoring Deno usage, alerting on unauthorized downloads, and correlating phishing incidents with process and registry telemetry during routine endpoint reviews. Implementing these measures emphasizes the importance of user reporting and rapid endpoint assessments following suspicious communications.

In conclusion, while Dindoor may not introduce entirely new techniques, its combination of trusted software, encoded scripts, and strategic system checks creates a potent threat that could help MuddyWater maintain access with minimal detection risk.

Cyber Security News Tags:Backdoor, Cybersecurity, Deno runtime, Dindoor, Iranian hackers, IT security, Malware, MuddyWater, phishing attacks, threat intelligence

Post navigation

Previous Post: Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL
Next Post: Claude Opus 4.6 Exploits Gym Booking Flaw in Tests

Related Posts

Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums Threat Actors Allegedly Selling Monolock Ransomware on Dark Web Forums Cyber Security News
KittySploit: AI-Driven PenTesting with Over 1150 Modules KittySploit: AI-Driven PenTesting with Over 1150 Modules Cyber Security News
Multiple Apache OpenOffice Vulnerabilities Leads to Memory Corruption and Unauthorized Content Loading Multiple Apache OpenOffice Vulnerabilities Leads to Memory Corruption and Unauthorized Content Loading Cyber Security News
Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts Critical DNN Platform Vulnerability Let Attackers Execute Malicious Scripts Cyber Security News
Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware Threat Actors Weaponizing .hwp Files to Deliver RokRAT Malware Cyber Security News
GenieLocker Ransomware Targets Multiple Systems GenieLocker Ransomware Targets Multiple Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Phishing Campaign Exploits RMM Tools
  • Chrome 152 Secures Over 300 Vulnerability Fixes
  • Claude Opus 4.6 Exploits Gym Booking Flaw in Tests
  • Iranian Hackers Exploit Developer Tool to Conceal Backdoor
  • Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Phishing Campaign Exploits RMM Tools
  • Chrome 152 Secures Over 300 Vulnerability Fixes
  • Claude Opus 4.6 Exploits Gym Booking Flaw in Tests
  • Iranian Hackers Exploit Developer Tool to Conceal Backdoor
  • Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark