Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Iranian Hackers Exploit Developer Tool to Conceal Backdoor

Iranian Hackers Exploit Developer Tool to Conceal Backdoor

Posted on August 26, 2026 By CWS

An Iranian-linked hacker group has been leveraging a legitimate developer tool to obscure a backdoor known as Dindoor within Windows operating systems. This tactic, which utilizes the Deno JavaScript and TypeScript runtime, allows the malware to operate under the guise of standard software processes.

Concealed Operations in Various Sectors

Dindoor has been deployed as a subsequent payload in targeted spearphishing attacks. Its presence has been detected in U.S. software and banking firms, as well as a Canadian non-profit, indicating its broad reach across multiple industries. The cybersecurity firm Binary Defense has been tracking this backdoor since early 2026, attributing the activity to the Iranian threat group known as MuddyWater.

According to a report shared with Cyber Security News, Dindoor’s approach combines a signed runtime and Base64 encoding, effectively evading traditional analysis. This method doesn’t rely on a single suspicious executable, but rather integrates familiar Windows utilities and a legitimate runtime to create a seemingly harmless delivery chain.

Detailed Infection Process

The infection process begins with a phishing attack that installs a loader on the target device. If the Deno runtime is not present, the malware uses the curl utility to download it, subsequently launching it with a Base64-encoded argument containing the Dindoor code. This installation, though not inherently suspicious, warrants scrutiny on non-developer systems, especially after phishing or unusual script activities.

The initial script executed by Dindoor gathers data from the compromised host and communicates with a remote server to compile a secondary payload. This payload retrieves and executes a third stage, creating a complex chain that complicates investigation and allows operators to modify components as needed.

Countermeasures and Detection Strategies

To establish persistence, Dindoor uses a Windows Run registry entry to launch a VBScript with wscript upon user login. This multi-stage tactic resembles previous strategies used by MuddyWater, designed to minimize visibility and maintain access.

Detection efforts must focus on behavior rather than static indicators. High-value signs include the execution of Deno with an unusually long encoded argument, unexpected curl activity, and registry entries pointing wscript to scripts in the AppData Local directory. Additionally, PowerShell queries for graphics adapters, indicative of virtual environments, should prompt further investigation.

Organizations can reduce their exposure by monitoring Deno usage, alerting on unauthorized downloads, and correlating phishing incidents with process and registry telemetry during routine endpoint reviews. Implementing these measures emphasizes the importance of user reporting and rapid endpoint assessments following suspicious communications.

In conclusion, while Dindoor may not introduce entirely new techniques, its combination of trusted software, encoded scripts, and strategic system checks creates a potent threat that could help MuddyWater maintain access with minimal detection risk.

Cyber Security News Tags:Backdoor, Cybersecurity, Deno runtime, Dindoor, Iranian hackers, IT security, Malware, MuddyWater, phishing attacks, threat intelligence

Post navigation

Previous Post: Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL

Related Posts

Evolution of DDoS Attacks Mitigation Strategies for 2025 Evolution of DDoS Attacks Mitigation Strategies for 2025 Cyber Security News
Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks Decoding PIN-Protected BitLocker Through TPM SPI Analysis To Decrypt And Mount The Disks Cyber Security News
Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak Beacon CRM Data Breach: Full Database Stolen After AWS Key Leak Cyber Security News
Iranian APT42 Enhances Phishing Tactics with AI Technology Iranian APT42 Enhances Phishing Tactics with AI Technology Cyber Security News
New GhostGrab Android Malware Silently Steals Banking Login Details and Intercept SMS for OTPs New GhostGrab Android Malware Silently Steals Banking Login Details and Intercept SMS for OTPs Cyber Security News
Malicious Extensions Target AI Chat Platforms Users Malicious Extensions Target AI Chat Platforms Users Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Iranian Hackers Exploit Developer Tool to Conceal Backdoor
  • Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL
  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Iranian Hackers Exploit Developer Tool to Conceal Backdoor
  • Global Cyber Fraud Crackdown Yields 58 Arrests: INTERPOL
  • Nutex Health Data Breach Exposes Sensitive Details
  • AI-Based Phishing Scheme Targets Apple Device Owners
  • Microsoft Teams Restores Services After Outage

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark