# Deno-Based Modular RAT & Internal Proxy Delivered via Mailbombing + Microsoft Teams Vishing ("DenoJSEnv")

> A targeted intrusion paired email mailbombing with Microsoft Teams voice phishing impersonating internal IT help desk to coerce an employee into running a Deno (JavaScript/TypeScript) runtime that loaded a modular Remote Access Trojan and internal SOCKS-like proxy. The implant provides WebSocket C2 over Amazon CloudFront, arbitrary command execution, host/network reconnaissance, registry Run-key persistence, and a loopback-based TCP pivot for lateral movement into non-internet-facing systems.

- **Published:** 2026-06-20T00:00:00Z
- **Last reviewed:** 2026-08-28T16:12:22.120Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0889
- **ID:** TL-2026-0889
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** MuddyWater (Iran)
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

InfoGuard Labs / DFIR.ch documented an in-the-wild intrusion (telemetry timestamped 2026-06-04, reported 2026-06-15) that abused the legitimate, security-hardened Deno runtime as a living-off-trusted-tooling execution host for a bespoke modular RAT.

Initial access was a two-stage social-engineering chain. First, a high-volume email mailbombing campaign flooded three targeted employees over the course of a single day to induce alert fatigue and manufacture a pretext for 'IT support' contact. Attackers then placed Microsoft Teams calls impersonating internal help-desk staff, citing internal company context and employee names likely harvested from public sources such as LinkedIn. The victim was directed to a fake self-service portal mimicking ServiceNow and downloaded a file named patch09913.b — actually a ZIP/tar archive — which was extracted to C:\Users\<user>\AppData\Roaming\DenoJSEnv. Execution was launched as: conhost --headless C:\Users\<user>\AppData\Roaming\DenoJSEnv\deno.exe --allow-run C:\Users\<user>\AppData\Roaming\DenoJSEnv\app.js, using conhost.exe --headless to suppress any visible window.

The RAT is composed of four JavaScript modules executed under Deno with deliberately scoped, high-risk permission flags. app.js is the dropper/orchestrator that spawns three child Deno processes with distinct permission sets. back.js is the C2 bridge: launched with --unsafely-ignore-certificate-errors --allow-run, it maintains a WebSocket (wss://) connection to an Amazon CloudFront endpoint (d2cff16eusb8mg.cloudfront.net), pushes reconnaissance (environment variables, network configuration, running processes via 'set && ipconfig /all && route print && tasklist'), and establishes persistence by writing the HKCU\Software\Microsoft\Windows\CurrentVersion\Run value Deno_AutoRun. helper.js (--allow-run --allow-env) is a stateless local HTTP server on 127.0.0.1:10021 that accepts POST /exec requests and pipes the body directly to cmd.exe /c, returning stdout/stderr as JSON. webui.js (--allow-net) listens on 127.0.0.1:10022 and exposes /connect, /send, and /closesocket endpoints implementing a SOCKS-like TCP proxy/pivot; internal traffic is base64-encoded and relayed back through back.js to the external WebSocket bridge, enabling access to internal hosts not reachable from the internet.

The modules use string-array shifting (array rotation) obfuscation to reconstruct meaningful strings at runtime. The intrusion was ultimately surfaced not by the initial implant but by follow-on LDAP queries and certificate-related reconnaissance. No threat actor attribution was asserted by the source; the TTPs (mailbomb + Teams vishing → fake ServiceNow/IT portal → signed/trusted runtime abuse) overlap with multiple financially and access-brokerage-motivated clusters observed using the same playbook in 2026.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1593 Search Open Websites/Domains
- T1566 Phishing
- T1204 User Execution
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1027 Obfuscated Files or Information
- T1564 Hide Artifacts
- T1684.001 Impersonation
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1057 Process Discovery
- T1018 Remote System Discovery
- T1087 Account Discovery
- T1071 Application Layer Protocol
- T1571 Non-Standard Port
- T1090 Proxy
- T1572 Protocol Tunneling
- T1132 Data Encoding
- T1021 Remote Services
- T1585 Establish Accounts
- T1566 Phishing
- T1656 Impersonation
- T1059 Command and Scripting Interpreter
- T1059 Command and Scripting Interpreter
- T1547 Boot or Logon Autostart Execution
- T1036 Masquerading
- T1071 Application Layer Protocol
- T1090 Proxy
- T1090 Proxy
- T1204 User Execution

## Sources

- [Anatomy of a Deno-Based Proxy & RAT](https://dfir.ch/posts/deno/)
- [Anatomy of a Deno-Based Proxy & RAT - InfoGuard Labs](https://labs.infoguard.ch/posts/anatomy_deno_rat/)
- [Malware Uses Deno Permission Flags to Run Commands and Proxy Internal Network Traffic](https://gbhackers.com/malware-uses-deno-permission-flags/)
- [Deno-Based Malware Abuses CloudFront WebSocket C2 for Remote Access and Internal Pivoting](https://cyberpress.org/deno-malware-enables-pivoting/)
- [Fake software on GitHub and SourceForge distribute Deno RAT - Malwarebytes](https://www.malwarebytes.com/blog/threat-intel/2026/05/fake-software-on-github-and-sourceforge-distribute-deno-rat)
- [Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware - Help Net Security](https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0889
