Threat actors are increasingly turning legitimate software into part of their attack chains. Instead of deploying an obviously malicious executable, attackers can abuse trusted tools that already have legitimate uses on Windows systems, making malicious activity harder to distinguish from normal software behavior. According to Cybersecurity News, Iran-linked operators are abusing the legitimate Deno JavaScript
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/iran-linked-hackers-abuse-legitimate-developer-tool-to-hide-dindoor-backdoor/
![]()

