Threat actors abuse Deno to run fileless malware in four intrusion cases

· Original article ↗

Summary

Sophos analyzed four 2026 intrusions in which attackers used malicious MSI installers and script loaders to deploy Deno, then ran obfuscated JavaScript in memory for host fingerprinting and command-and-control.

Key points

  • Initial access varied across cases and included ClickFix-style social engineering, web-delivered scripts, and a trojanized PsExec MSI promoted through a spoofed GitHub repository.
  • The recurring execution chain used MSI packages to install VBS and PowerShell loaders, which downloaded and installed the Deno runtime.
  • Attackers used trusted Windows utilities including msiexec, wscript, PowerShell, curl, and tar to stage payloads and blend activity with legitimate processes.
  • Deno ran Base64-encoded JavaScript in memory with unrestricted permissions; the payload fingerprinted hosts, checked C2 health endpoints, and could retrieve further payloads.
  • In one case, attackers established persistence through an HKCU Run key and later used a legitimate PsExec binary for discovery and credential dumping from the SAM registry hive.
  • Sophos reported detections at several stages and identified opportunities to flag unusual Deno behavior; it also shared related IoCs and countermeasures.

Article Details

Attack Vectors
  • A ClickFix-style prompt instructed a user to copy and run an obfuscated PowerShell command, which retrieved and launched a malicious MSI.
  • In a second case, an obfuscated command launched hidden PowerShell to retrieve and execute a remote script in memory. The precise web delivery mechanism was not confirmed.
  • In a third case, browser activity preceded PowerShell retrieval of a remote MSI; the report found no evidence that the user directly visited the malicious domain.
  • In a fourth case, a poisoned Bing search result apparently led a user to a spoofed GitHub repository, where they downloaded and executed a malicious MSI masquerading as PsExec.
  • Across the cases, malicious MSI packages dropped VBS and PowerShell loaders. The loaders installed Deno and ran obfuscated JavaScript payloads in memory.
Defensive Notes
  • Sophos reported detections at multiple stages, including remote MSI execution, ClickFix-style Run-dialog execution, and the PowerShell download of deno.exe.
  • The report identifies unexpected Deno behavior and suspicious downstream activity originating from Deno as detection opportunities.
  • The report says estates can manage Deno through Application Control / PUA rules (AppC/Deno-A) in Central.

Indicators of compromise

TypeIndicatorContext
DOMAINcrahdhduf[.]comC2 domain listed for cases 1 and 3.
DOMAINkoromoblog[.]comDomain the report identifies as malicious in the third case.
DOMAINserialmenot[.]comC2 domain listed for cases 2 and 4.
DOMAINypjkevsbsdhj[.]zhivachkapro[.]comC2 domain listed for case 2; also used in its malicious retrieval chain.
IPV4144[.]31[.]2[.]161C2 IP address listed for cases 1, 2, and 3.
SHA2562541d96d1d071f87127bf0714f70692d25e1946632457718c6f378fcc4a3dca2Hash of the Lynx_system59.vbs loader bundled in the malicious MSI.
SHA25674260ef8c440692043aaa4656947258b3acfc207c95f09682b69d031b42890a0Malicious PsExec.msi hash.
SHA256b0af82de672d81f3c2f153977923b3884a8a9e7045b182c2379b19a1996931a0Hash of the python85.ps1 loader bundled in the malicious MSI.

MITRE ATT&CK

T1003.002 · Security Account ManagerIn case 4, the attackers dumped credentials from the SAM registry hive.T1027 · Obfuscated Files or InformationThe JavaScript payload was Base64-encoded and used single-character function names; initial commands were also obfuscated.T1033 · System Owner/User DiscoveryThe JavaScript payload collected the infected device's username for its fingerprint.T1036.005 · Match Legitimate Resource Name or LocationThe malicious PsExec.msi was named and presented as a legitimate PsExec utility.T1047 · Windows Management InstrumentationIn case 3, PowerShell invoked the Win32_Product Install method through Invoke-CimMethod to install the downloaded MSI.T1059.001 · PowerShellPowerShell commands retrieved remote content, staged the MSI installers, and deployed Deno.T1059.005 · Visual BasicMSI-dropped VBS launchers invoked the PowerShell staging scripts.T1059.007 · JavaScriptDeno executed obfuscated JavaScript payloads supplied inline as Base64-encoded data.T1082 · System Information DiscoveryThe JavaScript payload collected system memory and OS release information for host fingerprinting.T1105 · Ingress Tool TransferLoaders downloaded Deno, and the JavaScript payload requested additional executable payloads from a C2 /mv2/ endpoint.T1204.002 · Malicious FileIn case 4, the user downloaded and directly executed a malicious MSI masquerading as PsExec.T1204.004 · Malicious Copy and PasteA ClickFix-style prompt instructed a user to copy and execute an obfuscated PowerShell command.T1218.007 · MsiexecThe intrusion chains used msiexec.exe to run malicious MSI packages.T1547.001 · Registry Run Keys / Startup FolderThe case 4 MSI set an HKCU Run value named Papa_software10 to relaunch its VBS loader.

People

Malware

Vendors

Products

Tools

Related Articles