[ << ALL_FEED ]

Ding, ding — who's there?

More in General

Ding, ding — who’s there? 🔔

The cyber intelligence group of Positive Technologies’ expert security center has discovered a new group that we have named DENOmination Group.

In 2026, we recorded its activity against Russian organizations in the defense-industrial, military, financial, and consulting sectors.

The key feature of the attacks is the use of the legitimate Deno runtime to execute malicious JavaScript/TypeScript code. In the investigated chains, we observed the DinDoor loader, the DenoRAT remote access agent, malicious MSI and LNK files, rotation of C2 infrastructure, and several related methods of initial delivery.

Overlaps in the codebase, configuration parameters, chain construction logic, and network infrastructure allowed us to link the observed episodes to the activity of a single group.

In the study, we analyzed the architecture of DinDoor and DenoRAT, the mechanisms of persistence and interaction with C2, infrastructure overlaps, TTPs, and a possible model of a shared platform being used by multiple operators.

Details — in our blog 🦖

#TI #APT #Malware
@ptescalator

More from ti_author

More from ti_author

More in General