DinDoor Backdoor Abuses Deno Runtime; Researchers Identify 20 Active C2 Servers

Summary
Analysis of two DinDoor samples details their Deno-based execution, victim fingerprinting, and C2 behavior. A query of HTTP response characteristics identified 20 servers active within the week before publication.
Key points
- The two analyzed MSI samples use PowerShell and the Deno runtime to execute malicious JavaScript, with differences in how their payloads are delivered.
- Both samples fingerprint infected systems using the username, hostname, memory, and OS release, and use a localhost TCP listener as a mutex.
- One sample contains a hardcoded JWT linked to campaign information and the domain serialmenot[.]com; the article describes the infrastructure as shared among multiple operators.
- A HuntSQL query based on HTTP response characteristics identified 20 matching servers across 15 autonomous systems, active within the week before publication.
- The article recommends monitoring unexpected Deno execution, suspicious command-line patterns and localhost binds, and restricting MSI execution where feasible.
Article Details
- Attack Vectors
- DinDoor is reportedly delivered through phishing or drive-by downloads using MSI installers.
- migcredit.pdf.msi uses a double extension to resemble a PDF document. The researchers suggest possible targeting of MigCredit, but do not confirm the delivery method or victim.
- The installers launch PowerShell scripts that install the legitimate Deno runtime if absent and execute attacker-controlled JavaScript without requiring administrator privileges.
- Installer_v1.21.66.msi displays a fabricated installation error while a VBS launcher silently starts PowerShell. Its JavaScript payload is passed directly to Deno as a base64 data URI rather than written to disk.
- Both variants fingerprint infected hosts and communicate with HTTP C2 endpoints. The Installer variant uses a hardcoded JWT, retrieves an in-memory second stage, and rotates its C2 index following failures.
- Defensive Notes
- Alert on unexpected deno.exe execution and restrict it to approved developer systems through application control where feasible.
- Restrict MSI execution to approved users or administrators using AppLocker or WDAC.
- Monitor for deno.exe -A data:application/javascript;base64 command lines and localhost TCP listeners on ports 10044 or 10091.
- Treat unexpected deno.exe processes launched beneath powershell.exe or wscript.exe as high-priority investigation leads.
- Review port 80 responses for the combined Via: 1.1 Caddy, 1.1 Caddy and X-Request-Id headers, particularly with a 404 Not Found response and Content-Length: 13. The researchers used this profile to identify 20 active hosts.
- The researchers describe an /health response of ok as an additional validation signal for active deployments; differing responses may reflect inactive or not-yet-operational infrastructure.
- Consider blocking the reported malicious domains and investigating communications with suspect hosting providers.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | aeeracaspsl[.]site | Domain resolving to reported DinDoor host 193.24.123[.]25. |
| DOMAIN | annaionovna[.]com | Domain resolving to reported DinDoor host 199.91.220[.]216. |
| DOMAIN | bitatits[.]surf | Domain resolving to reported DinDoor host 199.217.99[.]189. |
| DOMAIN | generalnewlong[.]com | Domain resolving to reported DinDoor host 192.109.200[.]151. |
| DOMAIN | hngfbgfbfb[.]cyou | Domain resolving to reported DinDoor host 85.192.27[.]152. |
| DOMAIN | ilspaeysoff[.]site | Domain resolving to reported DinDoor host 193.24.123[.]25. |
| DOMAIN | ineracaspsl[.]site | Domain resolving to reported DinDoor host 193.24.123[.]25. |
| DOMAIN | justtalken[.]com | TLS certificate common name on reported DinDoor host 194.48.141[.]192; resolution was not observed. |
| DOMAIN | landmas[.]info | Domain resolving to reported DinDoor host 146.19.254[.]84. |
| DOMAIN | myspaeysoff[.]site | Domain resolving to reported DinDoor host 193.24.123[.]25. |
| DOMAIN | playerdragonbike[.]com | Resolving domain and TLS certificate common name associated with reported DinDoor host 209.99.189[.]170. |
| DOMAIN | serialmenot[.]com | C2 domain used by Installer_v1.21.66.msi; described as shared multi-tenant malware infrastructure. |
| DOMAIN | weaplink[.]com | Domain resolving to reported DinDoor host 193.24.123[.]25. |
| HOSTNAME | agilemast3r[.]duckdns[.]org | Specific dynamic-DNS hostname resolving to reported DinDoor host 192.109.200[.]151. |
| HOSTNAME | bandage[.]healthydefinitetrunk[.]com | Resolving hostname and TLS certificate common name associated with reported DinDoor host 138.124.240[.]76. |
| HOSTNAME | grafana[.]healthydefinitetrunk[.]com | Resolving hostname associated with reported DinDoor host 138.124.240[.]77. |
| HOSTNAME | surgery[.]healthydefinitetrunk[.]com | Resolving hostname associated with reported DinDoor host 2.27.122[.]16. |
| IPV4 | 138[.]124[.]240[.]76 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 138[.]124[.]240[.]77 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 140[.]82[.]18[.]48 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 146[.]19[.]254[.]84 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 178[.]104[.]137[.]180 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 178[.]16[.]52[.]191 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 185[.]218[.]19[.]117 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 192[.]109[.]200[.]151 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 193[.]233[.]82[.]43 | Reported DinDoor server used to illustrate an HTTP request to the /health endpoint. |
| IPV4 | 193[.]24[.]123[.]25 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 194[.]48[.]141[.]192 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 199[.]217[.]99[.]189 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 199[.]91[.]220[.]142 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 199[.]91[.]220[.]216 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 2[.]26[.]117[.]169 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 2[.]27[.]122[.]16 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 209[.]99[.]189[.]170 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 45[.]135[.]180[.]200 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 45[.]151[.]106[.]88 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| IPV4 | 85[.]192[.]27[.]152 | Reported DinDoor infrastructure host identified through its HTTP response profile. |
| SHA256 | 2a09bbb3d1ddb729ea7591f197b5955453aa3769c6fb98a5ef60c6e4b7df23a5 | SHA-256 of the analyzed DinDoor sample Installer_v1.21.66.msi. |
| SHA256 | 7b793c54a927da36649eb62b9481d5bcf1e9220035d95bbfb85f44a6cc9541ae | SHA-256 of the analyzed DinDoor installer migcredit.pdf.msi. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationPayloads are base64-encoded, and the migcredit variant uses javascript-obfuscator with a shuffled 181-entry string array.T1033 · System Owner/User DiscoveryBoth variants include the system's USERNAME in their host fingerprint.T1036.007 · Double File Extensionmigcredit.pdf.msi uses a double extension to pass the malicious installer off as a PDF document.T1059.001 · PowerShellJuliet_widget15.ps1 and tango_utility84.ps1 install Deno if needed and launch the JavaScript payload.T1059.003 · Windows Command ShellThe migcredit installer launches its PowerShell script through cmd.exe.T1059.005 · Visual BasicInstaller_v1.21.66.msi uses error.vbs for a fabricated error dialog and Viper_controller36.vbs to silently launch PowerShell.T1059.007 · JavaScriptDinDoor runs attacker-controlled JavaScript using Deno; one variant executes it directly from a base64 data URI.T1071.001 · Web ProtocolsDinDoor communicates with C2 using HTTP GET health checks and recurring requests to /event or JWT-bearing /mv2 paths.T1082 · System Information DiscoveryBoth variants collect hostname, total memory, and OS release information to construct a host fingerprint.T1105 · Ingress Tool TransferDinDoor retrieves follow-on payloads; the Installer variant's second stage remains in memory.T1140 · Deobfuscate/Decode Files or InformationJuliet_widget15.ps1 decodes embedded base64 JavaScript before writing it to Uniform_system17.js.T1189 · Drive-by CompromiseThe article reports drive-by downloads as a DinDoor MSI delivery method.T1204.002 · Malicious FileExecution of the malicious MSI installers initiates the DinDoor infection chain.T1218.007 · Msiexecmsiexec.exe executes the malicious installers and initiates their script-based payload chains.T1497.001 · System ChecksThe Installer variant's child process enumerates GPUs using Get-WmiObject Win32_VideoController, which the researchers assess as likely sandbox checking.T1564.003 · Hidden WindowThe script launchers hide execution windows, including a VBS launcher that invokes PowerShell with window style 0.T1566 · PhishingThe article reports phishing as a DinDoor delivery method without establishing a specific phishing subtype.
People
Threat Actors
MuddyWaterReported alias of Seedworm. The analyzed Installer sample contains JWT metadata similar to activity associated with MuddyWater in JUMPSEC research.SeedwormBroadcom reportedly linked DinDoor activity targeting U.S. organizations to this Iranian APT group, also tracked as MuddyWater.TAG-150JUMPSEC reportedly attributed serialmenot[.]com to TAG-150 as a CastleLoader backend. The conclusion refers to TAG-150/GrayBravo and tentatively compares the financial-services lure with its activity.
Malware
CastleLoaderAs seen in other modular malware, threat actors have the ability to employ multiple variants of DinDoor while still staying under the Tsundere/CastleLoader umbrella.CastleRATcode-signing certificate referenced in research tied to MuddyWater, and Russian cybercrime actors using CastleRAT. The extracted information from the MSI is below:ChainShellnoting that JUMPSEC's research documents a separate component within the same threat cluster called ChainShell, a Node.js agent that resolves its C2 from an Ethereum smart contract. We observed no shared codeDinDoorwhich complicates detection in networks where these tools are allowlisted, and coverage is lacking. DinDoor, tracked as a variant of the Tsundere Botnet, follows this model.Tsundere Botnetwhere these tools are allowlisted, and coverage is lacking. DinDoor, tracked as a variant of the Tsundere Botnet, follows this model.
Vendors
Aeza Group LLCIP 85.192.27[.]152 N/A hngfbgfbfb[.]cyou AEZA GROUP LLC, DEBL Networkssingle provider accounting for a majority of the cluster. Several networks in Figure 05 (PROSPERO 000, BL Networks, ZhyouiSat Communications, and AEZA Group) have been identified as bulletproof hosters or slow toBlueVPS OUIP 146.19.254[.]84 N/A landmas[.]info BlueVPS OU, NLDigital Hosting Provider LLCIP 193.233.82[.]43 N/A N/A Digital Hosting Provider LLC, NLHetzner Online GmbHIP 178.104.137[.]180 N/A N/A Hetzner Online GmbH, DELet's Encryptour research, though a handful of hosts did have a TLS certificate subject common name (issued by Let's Encrypt) pointing to domains that could be used in future attacks. Domains registered via Tucows and usingMHost LLCIP 45.151.106[.]88 N/A N/A MHost LLC, NLNEKOBYTE INTERNATIONAL LIMITEDIP 138.124.240[.]76 bandage.healthydefinitetrunk[.]com bandage.healthydefinitetrunk[.]com NEKOBYTE INTERNATIONAL LIMITED, DENjallapointing to domains that could be used in future attacks. Domains registered via Tucows and using Njalla for DNS nameservers were seen consistently across the host results.Omegatech LTDIP 178.16.52[.]191 N/A N/A Omegatech LTD, DEPfcloud UGagilemast3r.duckdns[.]org Pfcloud UG, NLPROSPERO OOOaeeracaspsl[.]site PROSPERO OOO, RUSKN Subnet & Telecom LtdIP 209.99.189[.]170 playerdragonbike[.]com playerdragonbike[.]com SKN Subnet & Telecom Ltd, USSOLLUTIUM EU Sp z.o.o.IP 45.135.180[.]200 N/A N/A SOLLUTIUM EU Sp z.o.o., NLThe Constant Company, LLCIP 140.82.18[.]48 N/A N/A The Constant Company, LLC, USTucowsby Let's Encrypt) pointing to domains that could be used in future attacks. Domains registered via Tucows and using Njalla for DNS nameservers were seen consistently across the host results.VDSka hostingIP 194.48.141[.]192 justtalken[.]com N/A VDSka hosting, NLZhouyiSat CommunicationsIP 185.218.19[.]117 N/A N/A ZhouyiSat Communications, DE
Products
AppLockerRestrict MSI execution to specific users/admins: Restricting msiexec.exe via AppLocker or WDAC removes DinDoor's initial execution vector.CaddyVia: 1.1 Caddy, 1.1 CaddyDenoRuntime code environments like Node.js, Deno, and Python are increasingly being utilized as an instrument to execute malicious code. Rather than deploying traditional compiled implants, these trusted, signed runtimesMicrosoft WindowsUpon execution, the installer triggers error.vbs, which opens a fabricated Windows error dialog with the message, "Installation Failed!Node.jsRuntime code environments like Node.js, Deno, and Python are increasingly being utilized as an instrument to execute malicious code. Rather than deploying traditional compiled implants, these trusted, signed runtimesPowerShellDinDoor executes through the Deno runtime, a detection gap in environments where monitoring is tuned for PowerShell, Python, or Node.js but lacks coverage for Deno.WDACRestrict MSI execution to specific users/admins: Restricting msiexec.exe via AppLocker or WDAC removes DinDoor's initial execution vector.
Tools
HuntSQLSeveral elements of the above will be used to build a HuntSQL query. The Via: 1.1 Caddy, 1.1 Caddy header indicates at least two proxy hops between the internet-facing host and the backend application. The IPsjavascript-obfuscatorUnlike the Installer* sample, migcredit.pdf.msi's payload is processed through javascript-obfuscator, an open-source project using a 181-entry string array with a runtime shuffle function that prevents static resolutionmsitoolsThe metadata for this sample also follows a similar pattern to that of the above. Where things change, is running msitools against the MSI revealed the file was created using the WiX toolset for packaging the installer.WiX ToolsetThe metadata for this sample also follows a similar pattern to that of the above. Where things change, is running msitools against the MSI revealed the file was created using the WiX toolset for packaging the installer.
Countries
DEto produce a 16-character hex ID. This identifier is appended to every C2 request, allowing the operator to de-duplicate victim hosts server side. Below is a code snippet displaying the code responsible forIranNLagilemast3r.duckdns[.]org Pfcloud UG, NLRUaeeracaspsl[.]site PROSPERO OOO, RURussiaUnited StatesIP 140.82.18[.]48 N/A N/A The Constant Company, LLC, US