Threat actors abuse Deno to run fileless malware in four intrusion cases

Summary
Sophos analyzed four 2026 intrusions in which attackers used malicious MSI installers and script loaders to deploy Deno, then ran obfuscated JavaScript in memory for host fingerprinting and command-and-control.
Key points
- Initial access varied across cases and included ClickFix-style social engineering, web-delivered scripts, and a trojanized PsExec MSI promoted through a spoofed GitHub repository.
- The recurring execution chain used MSI packages to install VBS and PowerShell loaders, which downloaded and installed the Deno runtime.
- Attackers used trusted Windows utilities including msiexec, wscript, PowerShell, curl, and tar to stage payloads and blend activity with legitimate processes.
- Deno ran Base64-encoded JavaScript in memory with unrestricted permissions; the payload fingerprinted hosts, checked C2 health endpoints, and could retrieve further payloads.
- In one case, attackers established persistence through an HKCU Run key and later used a legitimate PsExec binary for discovery and credential dumping from the SAM registry hive.
- Sophos reported detections at several stages and identified opportunities to flag unusual Deno behavior; it also shared related IoCs and countermeasures.
Article Details
- Attack Vectors
- A ClickFix-style prompt instructed a user to copy and run an obfuscated PowerShell command, which retrieved and launched a malicious MSI.
- In a second case, an obfuscated command launched hidden PowerShell to retrieve and execute a remote script in memory. The precise web delivery mechanism was not confirmed.
- In a third case, browser activity preceded PowerShell retrieval of a remote MSI; the report found no evidence that the user directly visited the malicious domain.
- In a fourth case, a poisoned Bing search result apparently led a user to a spoofed GitHub repository, where they downloaded and executed a malicious MSI masquerading as PsExec.
- Across the cases, malicious MSI packages dropped VBS and PowerShell loaders. The loaders installed Deno and ran obfuscated JavaScript payloads in memory.
- Defensive Notes
- Sophos reported detections at multiple stages, including remote MSI execution, ClickFix-style Run-dialog execution, and the PowerShell download of deno.exe.
- The report identifies unexpected Deno behavior and suspicious downstream activity originating from Deno as detection opportunities.
- The report says estates can manage Deno through Application Control / PUA rules (AppC/Deno-A) in Central.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | crahdhduf[.]com | C2 domain listed for cases 1 and 3. |
| DOMAIN | koromoblog[.]com | Domain the report identifies as malicious in the third case. |
| DOMAIN | serialmenot[.]com | C2 domain listed for cases 2 and 4. |
| DOMAIN | ypjkevsbsdhj[.]zhivachkapro[.]com | C2 domain listed for case 2; also used in its malicious retrieval chain. |
| IPV4 | 144[.]31[.]2[.]161 | C2 IP address listed for cases 1, 2, and 3. |
| SHA256 | 2541d96d1d071f87127bf0714f70692d25e1946632457718c6f378fcc4a3dca2 | Hash of the Lynx_system59.vbs loader bundled in the malicious MSI. |
| SHA256 | 74260ef8c440692043aaa4656947258b3acfc207c95f09682b69d031b42890a0 | Malicious PsExec.msi hash. |
| SHA256 | b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0 | Hash of the python85.ps1 loader bundled in the malicious MSI. |
MITRE ATT&CK
T1003.002 · Security Account ManagerIn case 4, the attackers dumped credentials from the SAM registry hive.T1027 · Obfuscated Files or InformationThe JavaScript payload was Base64-encoded and used single-character function names; initial commands were also obfuscated.T1033 · System Owner/User DiscoveryThe JavaScript payload collected the infected device's username for its fingerprint.T1036.005 · Match Legitimate Resource Name or LocationThe malicious PsExec.msi was named and presented as a legitimate PsExec utility.T1047 · Windows Management InstrumentationIn case 3, PowerShell invoked the Win32_Product Install method through Invoke-CimMethod to install the downloaded MSI.T1059.001 · PowerShellPowerShell commands retrieved remote content, staged the MSI installers, and deployed Deno.T1059.005 · Visual BasicMSI-dropped VBS launchers invoked the PowerShell staging scripts.T1059.007 · JavaScriptDeno executed obfuscated JavaScript payloads supplied inline as Base64-encoded data.T1082 · System Information DiscoveryThe JavaScript payload collected system memory and OS release information for host fingerprinting.T1105 · Ingress Tool TransferLoaders downloaded Deno, and the JavaScript payload requested additional executable payloads from a C2 /mv2/ endpoint.T1204.002 · Malicious FileIn case 4, the user downloaded and directly executed a malicious MSI masquerading as PsExec.T1204.004 · Malicious Copy and PasteA ClickFix-style prompt instructed a user to copy and execute an obfuscated PowerShell command.T1218.007 · MsiexecThe intrusion chains used msiexec.exe to run malicious MSI packages.T1547.001 · Registry Run Keys / Startup FolderThe case 4 MSI set an HKCU Run value named Papa_software10 to relaunch its VBS loader.
People
Malware
Vendors
Products
CentralIndividual estates may also manage the Deno runtime via Application Control / PUA rules (AppC/Deno-A) in Central. Finally, a file containing Indicators of Compromise (IoCs) related to this research is available on ourDenoMDR investigated multiple intrusion cases involving a threat activity cluster that consistently abused Deno, a legitimate JavaScript and TypeScript runtime environment, to execute malicious JavaScript payloadsMicrosoft Windowsprompts instruct users to manually copy and execute obfuscated PowerShell commands, typically via the Windows Run dialog. This resulted in user-driven execution of PowerShell, which retrieved and launched aTaegisincluding contextual rules that can flag unruly downstream behavior that originated via Deno. A list of Taegis countermeasures able to detect activity associated with Deno abuse is published in the CTU post.WixThe analysis shows that the MSI file was built with WiX and uses standard installer features plus a custom action to drop and run VBS and PowerShell scripts “Lynx_system59.vbs” (SHA256: