Security1 distinct publisher3 min readUpdated
Attackers installed a legitimate JavaScript and TypeScript runtime on victim hosts to run payloads in memory. The middle of the chain barely varied, which is where detection work belongs.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Sophos MDR says it investigated multiple intrusion cases in early 2026 involving one threat activity cluster that consistently installed Deno, a legitimate JavaScript and TypeScript runtime, in order to execute malicious JavaScript directly in memory [1]. Initial access vectors differed between victims, but the malware, infrastructure and execution chains shared enough post-compromise behaviour that MDR describes a repeatable attack framework it continues to track [2][3].
The mechanic worth internalising is what Sophos calls Bring Your Own Runtime: rather than depend on whatever interpreters happen to exist on the host, the attackers downloaded and installed Deno themselves before running obfuscated JavaScript, mostly command-and-control payloads [4][5]. That converts execution from an environmental question into a delivery problem the attacker controls.
The staging around it is conventional. Social engineering, web-based delivery and malware masquerading as legitimate software provided the foothold; malicious MSI packages then dropped VBS and PowerShell loaders that retrieved, installed and executed the runtime [6][7]. Sophos reports heavy use of living-off-the-land binaries across both stages, naming msiexec, wscript, PowerShell, curl and tar [8]. The documented progression runs from PowerShell or command-based staging, to MSI execution, to VBS and PowerShell loaders, to Deno runtime deployment, to in-memory payload execution [9]. Of those five stages, the three in the middle held steady while variation clustered at the front, in initial access, and at the back, in secondary payload deployment [10][11]. Sophos states that staging mechanisms, runtime deployment techniques and C2 design remained highly consistent [12]. In one figure the firm compares process trees across four victims and reports that similarities outweigh differences [13].
The JavaScript run through Deno performed host fingerprinting, execution control checks and persistent C2 communication, and in some cases pulled and ran further payloads [14]. Those are ordinary capabilities. The point is the pathway they arrived on.
Sophos's own framing of the defensive problem is the part to argue with or act on: security tooling and behavioural detections are often optimised around established attack pathways and commonly abused scripting engines, and it reads the adoption of Deno as a move toward less commonly monitored runtimes for reliable execution [15][16]. That is a single vendor characterising its own telemetry, but it is testable in-house this week. If a detection stack alerts on PowerShell and wscript behaviour but treats an unfamiliar signed runtime binary spawning network-connected child processes as noise, the gap is specific and closable: inventory which interpreters your detections actually name, and check whether runtime installation by an MSI custom action or a loader script produces any alert at all.
Corroboration is thin but not absent. Sophos's Counter Threat Unit has been tracking ClickFix-involved Deno abuse in a later evaluation window and has published its own account [17], and Sophos points to ThreatDown documentation of a similar intrusion chain using Deno-based JavaScript execution to deliver Castle RAT [18].
What to watch: whether the uniform middle segment stays uniform, because that is where durable detection value sits, and whether the same BYOR pattern shows up with other runtimes now that the technique has been written up. Sophos also says its report includes analysis of a recovered malicious MSI covering staging, persistence, custom actions and payload delivery [19]; that artefact detail is where hunt queries will come from.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Although initial access vectors varied among victims, analysis of the observed malware, infrastructure and execution chains revealed a shared set of post-compromise behaviours and tooling.
While initial access vectors varied, subsequent actions remained uniform, leading to variation again later in the chain at Deno-based JavaScript execution and C2 communication, with variations in secondary payload deployment across affected victims.
Sophos assesses that the threat actor's adoption of Deno reflects a shift toward using less commonly monitored runtime environments to facilitate reliable payload execution through potentially unmonitored pathways.
Sophos' Counter Threat Unit has been watching the evolution of ClickFix-involved Deno abuse and has published a description of what it sees from its perspective in a later evaluation window.
Sophos says ThreatDown documented a similar intrusion chain involving Deno-based JavaScript execution and the delivery of Castle RAT.
The Sophos report presents detailed analysis of a recovered malicious MSI file covering the threat actor's staging mechanisms, persistence techniques, custom actions and payload delivery methods.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Strong first-party IR detail, single vendor, artefacts partly withheld
The claims rest on Sophos MDR's own incident response: a named five-stage chain, a concrete msiexec command line from the ClickFix case, an enumerated LOLBin set, and a four-victim process-tree comparison. That is direct observational evidence rather than speculation. It is capped by being one publisher with no independent source in the cluster, by the promised MSI teardown and any IOC or detection content not appearing in the captured text, and by the 'growing adoption of alternative runtimes' framing carrying no comparative measurement.
Technique observed in a handful of real intrusions, scale unknown
Adoption here means attacker uptake of the BYOR/Deno technique, and it is real but small-n: multiple Sophos MDR cases in early 2026 with four compared in detail, four distinct initial-access variants, and one second-hand parallel report from ThreatDown involving Castle RAT. No victim counts, sectors, geographies, or trend series are given, and no prevalence comparison against already-monitored runtimes, so the technique reads as established-but-niche rather than widespread.
Mechanics well-scoped; trend framing runs slightly ahead of the sample
The technical body is restrained and hedged (delivery mechanism for case two explicitly unconfirmed), and the headline mechanics match what was observed. The mild overstatement is at the framing layer: 'growing adoption of alternative runtime environments' and a shift toward 'less commonly monitored' runtimes are trend and detection-gap assertions generalised from four cases plus one cited third-party report, with no measurement of coverage gaps in real tooling and no IOC/rule material to let readers test the gap themselves.
Vendor threat research promoting its own MDR and CTU capability
The single source is a security vendor's own blog reporting work performed by its managed detection and response arm, and it cross-links a companion post from its Counter Threat Unit. Publishing evidence that mainstream detections miss alternative runtimes directly supports demand for that vendor's monitoring services. This is normal, disclosed vendor research with genuine incident data behind it rather than concealed promotion, so the incentive is moderate: it shapes framing (defender blind spots, 'continues to track') more than it undermines the observations.
Credible mechanics, unreplicated within this cluster
Confidence is held mid-range by a real tension: the observations come from hands-on incident response with concrete artefacts, which is high-quality input, but the cluster contains exactly one publisher, that publisher has a service incentive, the corroborating ThreatDown and CTU material is referenced rather than supplied, and the captured text is truncated before the MSI analysis. The chain mechanics can be relied on with care; the broader trend claim should be treated as provisional.
security
ClickFix operators install the signed Deno runtime to run their remote JavaScript1 distinct publisher
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
build
Allow-list the closed set, block-list the open one: 193 thin geo pages, one gate1 distinct publisher
build
The third answer: a dead-code tool allowed to say "not traced yet"1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 10, 2026