Technologies
Back
Cybersecurity & Privacy

DENOmination Group: Deno in attack chains against Russian organizations

Habr
Advertisement468 × 90
DENOmination Group: Deno in attack chains against Russian organizations

PT ESC cyber intelligence specialists have identified a series of attacks targeting Russian organizations, including defense industry enterprises, financial institutions, and military agencies. The attackers utilize the legitimate Deno runtime environment to execute malicious JavaScript code. The primary tools identified include the DinDoor loader and the full-featured DenoRAT backdoor. The investigation revealed two main infection chains involving malicious MSI files and LNK shortcuts distributed via phishing campaigns. Experts also discovered the DeltaScan installer, which follows a similar multi-stage execution pattern. The use of shared techniques and infrastructure points to the activity of a single threat actor dubbed the DENOmination Group. This campaign highlights the growing trend of leveraging legitimate software to stealthily execute malicious operations within corporate networks.

This is a summary. Read the full article at the original source:

Habr
Advertisement468 × 90
Share
Cybersecurity & Privacy

Related stories

Advertisement970 × 250