Tsundere is the operator designation for a Russian-speaking threat actor associated with the Tsundere botnet, an emerging Windows-focused malware operation built around Node.js and blockchain-assisted command-and-control discovery. The activity is notable for using a fake MSI-based installer chain to deploy Node.js and legitimate libraries, then enabling arbitrary JavaScript execution on compromised hosts through a WebSocket-based control channel. A distinctive feature of the operation is its use of an Ethereum smart contract, disguised as an ERC-20 token under the name MisakaNetwork, to store and rotate command-and-control information, allowing resilient and dynamically updated infrastructure discovery. The actor’s tooling indicates an emphasis on flexibility, modularity, and operational agility. Infected systems retrieve command-and-control details from the blockchain, validate the resolved endpoint, establish a WebSocket session, and execute JavaScript tasks supplied by the operator. Reported variants linked to the botnet include DinDoor. The operation has also been observed using Rclone in support of access to cloud-hosted infrastructure, including Wasabi-backed storage, reflecting overlap with broader trends in abuse of legitimate cloud services for staging or exfiltration. Tsundere infrastructure and tradecraft have shown links to other criminal tooling ecosystems. The botnet has been reported to share infrastructure with 123 Stealer, and its development style has been compared to an earlier Russian npm-based malware campaign. Separate reporting has attributed a Tsundere dropper to a Russian-speaking actor referred to as koneko, suggesting either direct authorship, a sub-operator identity, or a closely associated developer within the same ecosystem. High-confidence public reporting supports characterization of the actor as Russian-speaking, but stronger attribution to a specific state or formal organization is not currently available. Operational overlap has also been observed between Tsundere tooling and infrastructure used by other threat actors. A Tsundere dropper was identified on infrastructure associated with MuddyWater, but it was assessed as external tooling rather than native MuddyWater malware, indicating reuse, acquisition, or opportunistic adoption of Tsundere capabilities by unrelated operators. Overall, Tsundere represents a technically distinctive botnet operator that combines commodity deployment methods, legitimate runtime components, blockchain-based command-and-control resolution, and script-driven post-compromise flexibility.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian-operated cybercrime botnet/C2 marketplace infrastructure offering bot access, payload generation, SOCKS proxying, and blockchain-based C2 rotation; its tooling was found deployed alongside MuddyWater infrastructure.
Tsundere is described as an emerging botnet abusing blockchain and Node.js components.
Tsundere is a newly emergent botnet targeting Windows systems, capable of executing arbitrary JavaScript code. It is distributed via a fake MSI installer that delivers Node.js and legitimate libraries. The botnet uses the Ethereum blockchain to retrieve WebSocket C2 server details, enabling infrastructure rotation and dynamic code execution.
Its DinDoor variant used Rclone to access a Wasabi server for cloud interaction/exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.