DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers
Reported 23 Apr 2026 by otx · Severity: medium
DinDoor is a Deno-based backdoor delivered via MSI files that exploits the Deno runtime to execute obfuscated JavaScript for command and control communications and system fingerprinting. Two analyzed samples show different execution behaviors: one writes JavaScript to disk while