Threat reportMalwareTL-2026-0889
Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv")
Deno-Based Modular RAT & Internal Proxy Delivered via (TL-2026-0889), also tracked as DenoJSEnv RAT, is a high-severity malware campaign, first published 2026-06-20 and last reviewed 2026-08-28. It is attributed to MuddyWater (Iran) with medium confidence, affects Microsoft Windows, maps to 23 MITRE ATT&CK techniques (T1016, T1018, T1021), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 1MuddyWater
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-0889
- Threat ID
- TL-2026-0889
- Also known as
- DenoJSEnv RAT, Deno-Based Proxy & RAT
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- MuddyWater
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Iran
- Motivation
- espionage
- Target sectors
- enterprise, technology
- Target regions
- Europe
- Detection rules
- 9
- Indicators of compromise
- 25
- Updates
- 2026-08-28 · revalidated 1× · latest source
Malware and tooling in Deno-Based Modular RAT & Internal Proxy Delivered via
Malware and tooling: DenoJSEnv RAT, Deno
How Deno-Based Modular RAT & Internal Proxy Delivered via works
A targeted intrusion paired email mailbombing with Microsoft Teams voice phishing impersonating internal IT help desk to coerce an employee into running a Deno (JavaScript/TypeScript) runtime that loaded a modular Remote Access Trojan and internal SOCKS-like proxy. The implant provides WebSocket C2 over Amazon CloudFront, arbitrary command execution, host/network reconnaissance, registry Run-key persistence, and a loopback-based TCP pivot for lateral movement into non-internet-facing systems.
InfoGuard Labs / DFIR.ch documented an in-the-wild intrusion (telemetry timestamped 2026-06-04, reported 2026-06-15) that abused the legitimate, security-hardened Deno runtime as a living-off-trusted-tooling execution host for a bespoke modular RAT.
Initial access was a two-stage social-engineering chain. First, a high-volume email mailbombing campaign flooded three targeted employees over the course of a single day to induce alert fatigue and manufacture a pretext for 'IT support' contact. Attackers then placed Microsoft Teams calls impersonating internal help-desk staff, citing internal company context and employee names likely harvested from public sources such as LinkedIn. The victim was directed to a fake self-service portal mimicking ServiceNow and downloaded a file named patch09913.b — actually a ZIP/tar archive — which was extracted to C:\Users\<user>\AppData\Roaming\DenoJSEnv. Execution was launched as: conhost --headless C:\Users\<user>\AppData\Roaming\DenoJSEnv\deno.exe --allow-run C:\Users\<user>\AppData\Roaming\DenoJSEnv\app.js, using conhost.exe --headless to suppress any visible window.
The RAT is composed of four JavaScript modules executed under Deno with deliberately scoped, high-risk permission flags. app.js is the dropper/orchestrator that spawns three child Deno processes with distinct permission sets. back.js is the C2 bridge: launched with --unsafely-ignore-certificate-errors --allow-run, it maintains a WebSocket (wss://) connection to an Amazon CloudFront endpoint (d2cff16eusb8mg.cloudfront.net), pushes reconnaissance (environment variables, network configuration, running processes via 'set && ipconfig /all && route print && tasklist'), and establishes persistence by writing the HKCU\Software\Microsoft\Windows\CurrentVersion\Run value Deno_AutoRun. helper.js (--allow-run --allow-env) is a stateless local HTTP server on 127.0.0.1:10021 that accepts POST /exec requests and pipes the body directly to cmd.exe /c, returning stdout/stderr as JSON. webui.js (--allow-net) listens on 127.0.0.1:10022 and exposes /connect, /send, and /closesocket endpoints implementing a SOCKS-like TCP proxy/pivot; internal traffic is base64-encoded and relayed back through back.js to the external WebSocket bridge, enabling access to internal hosts not reachable from the internet.
The modules use string-array shifting (array rotation) obfuscation to reconstruct meaningful strings at runtime. The intrusion was ultimately surfaced not by the initial implant but by follow-on LDAP queries and certificate-related reconnaissance. No threat actor attribution was asserted by the source; the TTPs (mailbomb + Teams vishing → fake ServiceNow/IT portal → signed/trusted runtime abuse) overlap with multiple financially and access-brokerage-motivated clusters observed using the same playbook in 2026.
MITRE ATT&CK techniques used in TL-2026-0889
Discovery
T1016 System Network Configuration Discovery; T1018 Remote System Discovery; T1057 Process Discovery; T1082 System Information Discovery; T1087 Account Discovery
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1564 Hide Artifacts; T1656 Impersonation
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1132 Data Encoding; T1571 Non-Standard Port; T1572 Protocol Tunneling
Persistence
T1547 Boot or Logon Autostart Execution
Initial Access
Resource Development
Reconnaissance
T1589 Gather Victim Identity Information; T1593 Search Open Websites/Domains
stealth
Affected products and versions in Deno-Based Modular RAT & Internal Proxy Delivered via
Remediation for Deno-Based Modular RAT & Internal Proxy Delivered via
Immediate actions
- Block and alert on the CloudFront C2 endpoint d2cff16eusb8mg.cloudfront.net at the web proxy/DNS/firewall
- Hunt for deno.exe executing from user-writable paths (AppData\Roaming\DenoJSEnv) and for conhost --headless launching deno.exe
- Search for and remove the HKCU\Software\Microsoft\Windows\CurrentVersion\Run value 'Deno_AutoRun'
- Hunt for the five known SHA-256 hashes (app.js, back.js, helper.js, webui.js, patch09913.b) across endpoints
- Isolate hosts with listeners on 127.0.0.1:10021 or 127.0.0.1:10022 spawned by deno.exe
Workarounds
- Disable or tightly restrict external Microsoft Teams calls/chat from outside the organization
- Block downloads of archive files with anomalous extensions (e.g. .b) at the mail/web gateway
Longer-term hardening
- Deploy EDR detections for Deno/Node/Bun runtimes invoked with high-risk permission flags (--allow-run, --allow-net, --allow-env, --unsafely-ignore-certificate-errors)
- Application control / WDAC allow-listing to prevent execution of unsanctioned interpreters from user profile directories
- Correlate Microsoft Teams external-call / impersonation events in the Unified Audit Log with mailbombing spikes for pre-execution warning
- User awareness training on mailbomb-then-call IT-impersonation vishing and fake ServiceNow self-service portals
- Restrict and monitor external Microsoft Teams federation / unmanaged-tenant chat and calls
Timeline of Deno-Based Modular RAT & Internal Proxy Delivered via
- Rapid7/Lyrie Research publish research documenting MuddyWater's use of Microsoft Teams-based IT-helpdesk impersonation as a false-flag-ransomware initial-access TTP, establishing the pattern this intrusion reuses.
- Later reporting refines the mailbombing start to roughly 24 hours before the 2026-06-04 Teams-vishing call, i.e. beginning 2026-06-03 rather than same-day.
- Intrusion surfaced via follow-on LDAP queries and certificate-related reconnaissance rather than the initial C2 implant itself.
- Reconnaissance executed via 'set && ipconfig /all && route print && tasklist' and relayed to C2; internal pivot established through base64-framed proxy.
- back.js writes HKCU Run value 'Deno_AutoRun' and opens a WebSocket C2 channel to d2cff16eusb8mg.cloudfront.net; helper.js (10021) and webui.js (10022) loopback services start.
- Implant executed at 2026-06-04T15:12:05 via 'conhost --headless deno.exe --allow-run app.js'; app.js spawns back.js, helper.js, and webui.js.
- Victim directed to a fake ServiceNow-style self-service portal and downloads patch09913.b (a ZIP/tar archive), extracted to AppData\Roaming\DenoJSEnv.
- Attackers place Microsoft Teams calls impersonating internal help-desk staff, using employee names and internal context likely sourced from LinkedIn.
- High-volume email mailbombing campaign floods three targeted employees over the course of a single day to induce alert fatigue and pretext IT-support contact.
- Daylight AI publishes a closely related Deno-RAT intrusion ('DinDoor') using the same module set and Deno_AutoRun persistence but a different C2 domain and sample hashes, assessed as consistent with MuddyWater/Seedworm tradecraft.
- InfoGuard Labs / DFIR.ch publish 'Anatomy of a Deno-Based Proxy & RAT' with full IOCs and TTP analysis.
- GBHackers and CyberPress republish technical analysis of the InfoGuard findings, reiterating Deno-execution detection guidance.
Update history for TL-2026-0889
- 2026-08-28 — Deno-Based Proxy & RAT Deployed via Mailbombing and Fake Teams IT-Support Impersonation: What changed No field escalations: severity/exploitability/status are unchanged (HIGH/ACTIVE/ACTIVE), and the newer report actually expresses LOWER attribution confidence (LOW vs. existing MEDIUM) and hedges the MuddyWater/Seedworm link as
Sources cited for Deno-Based Modular RAT & Internal Proxy Delivered via
- Anatomy of a Deno-Based Proxy & RAT
- Anatomy of a Deno-Based Proxy & RAT - InfoGuard Labs
- Malware Uses Deno Permission Flags to Run Commands and Proxy Internal Network Traffic
- Deno-Based Malware Abuses CloudFront WebSocket C2 for Remote Access and Internal Pivoting
- Fake software on GitHub and SourceForge distribute Deno RAT - Malwarebytes
- Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security
Detection coverage for TL-2026-0889
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0889 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.