DENOmination Group: Deno in attack chains against Russian organizations

PT ESC cyber intelligence specialists have identified a series of attacks targeting Russian organizations, including defense industry enterprises, financial institutions, and military agencies. The attackers utilize the legitimate Deno runtime environment to execute malicious JavaScript code. The primary tools identified include the DinDoor loader and the full-featured DenoRAT backdoor. The investigation revealed two main infection chains involving malicious MSI files and LNK shortcuts distributed via phishing campaigns. Experts also discovered the DeltaScan installer, which follows a similar multi-stage execution pattern. The use of shared techniques and infrastructure points to the activity of a single threat actor dubbed the DENOmination Group. This campaign highlights the growing trend of leveraging legitimate software to stealthily execute malicious operations within corporate networks.
This is a summary. Read the full article at the original source:
HabrRelated stories
In the modern internet landscape, using a Web Application Firewall (WAF) has become an essential standard for securing digital resources. This article…
AdGuard is offering a limited-time promotion on its Family Plan, providing a lifetime license for $14.97, a significant discount from its regular $169…
Security researchers and tech reviewers from Gamers Nexus and Level1Techs have raised concerns regarding the privacy practices of LG televisions. Inve…



