Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Chrome 101 Patches 41 Vulnerabilities, 6 Critical Memory Bugs
August 7, 2026
Patchwork APT Uses Fake PDFs, Chat Apps to Spy on PCs, Android
August 7, 2026
Claude in Chrome Prompt Injection Steals Gmail Codes to Hijack Slack, X, and Claude.ai Accounts
August 7, 2026
Home/Threats/Fake AI Installers Deploy DinDoor Backdoor on Windows Systems
Threats

Fake AI Installers Deploy DinDoor Backdoor on Windows Systems

Key Takeaways A new malware campaign is distributing the DinDoor backdoor and a sophisticated Deno-based Remote Access Trojan (RAT) via fake installers for popular AI tools like ChatGPT and Claude,...

Jennifer sherman
Jennifer sherman
May 27, 2026 5 Min Read
59 0

Key Takeaways

  • A new malware campaign is distributing the DinDoor backdoor and a sophisticated Deno-based Remote Access Trojan (RAT) via fake installers for popular AI tools like ChatGPT and Claude, as well as creative software.
  • The campaign targets Windows users, particularly content creators, gamers, and AI enthusiasts, leveraging compromised YouTube channels and trusted platforms like GitHub and SourceForge for distribution.
  • The Deno RAT is highly intrusive, capable of stealing data from browsers and crypto wallets, capturing screenshots, logging clipboard activity, and even live-streaming the victim’s screen through a hidden Microsoft Edge process.
  • The threat actors employ stealthy tactics, including using legitimate package managers (Scoop, WinGet) and Cloudflare Workers, to evade detection and maintain anonymity.

A new, widespread malware campaign is actively exploiting the popularity of artificial intelligence tools, targeting a broad audience including content creators, gamers, and AI enthusiasts. Threat actors are deploying deceptive installers that masquerade as legitimate software, such as ChatGPT and Claude, to implant the potent DinDoor backdoor on compromised Windows systems. This sophisticated operation was recently detailed in a report by Malwarebytes.

Table Of Content

  • Key Takeaways
  • How the DinDoor Backdoor Infects Victims
  • The Deno RAT and Its Hidden Capabilities
  • What You Should Do

The campaign has achieved significant reach, partly due to its use of compromised YouTube channels to direct victims to the malicious files. Videos promoting these fake installers have garnered over 50,000 views, indicating a substantial number of potential victims.

Malwarebytes researchers uncovered the campaign after identifying suspicious fake installers and plugins hosted on reputable platforms like GitHub and SourceForge. The malicious software impersonates well-known brands, including AI chatbots ChatGPT and Claude, alongside creative applications such as Ableton Live, AutoTune, and Kontakt, making the deception highly convincing for unsuspecting users who trust these names and platforms.

The attackers strategically leverage the credibility of these legitimate development and open-source platforms to lend an air of authenticity to their fake projects. Given that GitHub and SourceForge are widely trusted by millions of developers and everyday users, victims are less likely to question the legitimacy of the files they are downloading.

According to the Malwarebytes report, once installed, DinDoor establishes a persistent backdoor connection to a command-and-control (C2) server, subsequently delivering a fully-featured remote access Trojan (RAT). This RAT possesses extensive capabilities, including stealing data from web browsers and cryptocurrency wallets, capturing screenshots, recording clipboard activity, and even covertly monitoring victims through a hidden video stream facilitated by the Microsoft Edge browser.

How the DinDoor Backdoor Infects Victims

The infection chain typically commences when a user visits a malicious GitHub or SourceForge repository and executes a provided command in their terminal, under the false impression that they are installing legitimate software. This single command silently downloads and runs an MSI installer file using Windows’ native installer tool, initiating the entire compromise sequence. The MSI file then drops a command (CMD) file and a PowerShell script onto the victim’s machine.

The PowerShell script proceeds to install the Deno JavaScript runtime using standard Windows package managers, Scoop and WinGet. This tactic helps the malicious activity appear less suspicious to security monitoring tools. With Deno in place, it fetches and executes the DinDoor backdoor directly from the attacker’s server.

DinDoor ensures its persistence on the system by creating a Windows registry run key, which guarantees the malware relaunches with every system boot. The backdoor then quietly communicates with its C2 server, retrieving additional payloads and exfiltrating information about the compromised system.

It’s important to note that the attackers are not exclusively focusing on AI chatbot lures. DinDoor has also been distributed through SourceForge pages impersonating a game booster called GearUP and an AI watermark remover named BWR, demonstrating a broader targeting strategy.

The Deno RAT and Its Hidden Capabilities

The RAT delivered by DinDoor is also built upon the Deno JavaScript runtime and is equipped with a comprehensive suite of espionage and data theft tools. It specifically targets over 50 cryptocurrency wallet browser extensions and standalone software wallets, including prominent names like Atomic Wallet, Exodus, and Electrum, posing a significant financial risk to cryptocurrency users.

One of the RAT’s most distinctive features is its peer-to-peer video streaming functionality, which cleverly abuses the Microsoft Edge browser. The RAT silently launches a hidden Edge process, injects a small web page into it, and then utilizes this page to stream live video of the victim’s screen directly to the attacker. This peer-to-peer method bypasses central servers, making detection considerably more challenging.

Beyond video streaming, the RAT supports SOCKS5 proxy tunnels, offers full remote desktop control through a customized VNC setup, and can execute arbitrary commands via PowerShell. Researchers also discovered a lighter variant of the RAT, dubbed “agent-lite,” which routes its C2 communications through Cloudflare Workers for enhanced anonymity and evasion.

What You Should Do

  • Download Software from Official Sources: Always obtain software directly from the official vendor’s website. Avoid third-party repositories, torrent sites, or links found on unofficial forums and social media.
  • Verify Digital Signatures: Before running any executable file, check its digital signature and publisher information through Windows Properties. Discrepancies or missing signatures are strong indicators of malicious intent.
  • Be Skeptical of “Free” or “Cracked” Software: Exercise extreme caution with offers of free or “cracked” versions of paid software. These are common vectors for malware distribution.
  • Educate Yourself and Your Users: Stay informed about common social engineering tactics and distribution methods used by threat actors.
  • Use Reputable Antivirus/Endpoint Detection & Response (EDR): Ensure your systems are protected by up-to-date antivirus software or EDR solutions capable of detecting and blocking malicious activity.
  • Monitor for Suspicious Network Activity: Keep an eye on outbound network connections for unusual traffic patterns, especially to known C2 domains or IP addresses.

Indicators of Compromise (IoCs):-

Type Indicator Description
URL https[:]//github.com/claude-free-plugin/ Malicious GitHub repository distributing fake Claude installer
URL https[:]//github.com/ai-gen-profi Malicious GitHub repository for fake AI software
URL https[:]//github.com/wharfdemolisherpit Malicious GitHub repository for fake software
URL https[:]//sourceforge.net/projects/gearup/ Fake GearUP game booster on SourceForge
URL https[:]//sourceforge.net/projects/bluewaveremover/ Fake BWR AI watermark remover on SourceForge
Domain claudescript[.]top Distribution website for DinDoor malware
Domain ms-telemetry-gateway-us[.]com Command-and-Control (C2) server
Domain dakatawebstick[.]com Command-and-Control (C2) server
Domain ashpaltlonpro[.]com Command-and-Control (C2) server
Domain cf-proxy[.]cloud-analytics-services[.]workers.dev Cloudflare-based C2 server
Domain agilemast3r[.]duckdns[.]org Command-and-Control (C2) server
Domain geralnewlong[.]com Command-and-Control (C2) server
Domain hngfbgfbfb[.]cyou Command-and-Control (C2) server
Domain logicalnewrestore[.]com Command-and-Control (C2) server
IP Address 23[.]227[.]196[.]107 Command-and-Control (C2) server
IP Address 45[.]137[.]99[.]121 Command-and-Control (C2) server
IP Address 31[.]57[.]129[.]23 Command-and-Control (C2) server
IP Address 66[.]78[.]40[.]107 Command-and-Control (C2) server
IP Address 193[.]233[.]198[.]132 Command-and-Control (C2) server

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackHackerMalwareSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

CISOs Boost Risk Visibility to Achieve Zero Critical Incidents

Next Post

npm Registry Flaw Lets Attackers Distribute Malware, Steal Wallets

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
UNC6671 Automates Microsoft 365 Data Theft via Session Hijacking
August 7, 2026
Papyrus Ad Fraud Abuses Hidden WebViews to Fake User Engagement
August 7, 2026
Critical Flaws in Enterprise Java Platforms Let Attackers Execute Remote Code
August 7, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us