Malware
DinDoor
- First Reported
- Apr 21, 2026
- Latest Reported
- Jul 15, 2026
Reported Context (2)
- command in a Finance customer's environment. Further investigation found that the command installs DinDoor, a Deno-based loader, DenoRAT, a Deno-based Remote Access Trojan (RAT), and NightshadeC2, a sophisticated eSentire Details TAG-150’s ClickFix Chain Delivering DinDoor, DenoRAT and NightshadeC2
- which complicates detection in networks where these tools are allowlisted, and coverage is lacking. DinDoor, tracked as a variant of the Tsundere Botnet, follows this model. DinDoor Backdoor Abuses Deno Runtime; Researchers Identify 20 Active C2 Servers
Malware (6)
People (1)
Threat Actors (3)
MITRE ATT&CK (32)
Vendors (19)
Products (104)
Tools (7)
Industries (2)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.