Tsunami, also known as Kaiten, is a long-running UNIX and Linux IRC-controlled backdoor and DDoS botnet family first observed in 2002. It targets Linux servers and IoT devices, including routers and DVRs, and has numerous modified variants, including Ziggy and malware tracked as Muhstik. Once installed, Tsunami connects to IRC command-and-control infrastructure, accepts remote shell and payload-management commands, and can conduct TCP, UDP, SYN, and ACK flooding attacks. Variants perform network and Telnet/SSH weak-password scanning, exploit exposed services, and use compromised systems to propagate to further targets. Tsunami has been deployed alongside cryptocurrency miners, including in operations exploiting vulnerable internet-facing applications and exposed container environments. Observed persistence and evasion include startup-script or cron-based execution, process-name masquerading, and log-cleaning activity. Tsunami has been used by multiple threat actors; operational reporting has linked variants and supporting infrastructure to Keksec and TeamTNT activity.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
9 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During the implant phase, Muhstik forces targeted GPON devices to download muhstik.tsunami malicious code.
During the implant phase, Muhstik forces targeted GPON devices to download muhstik.tsunami malicious code.
There is a critical vulnerability in Apache Log4j versions 2.0 to 2.14.1, a widely used software library for Java applications. The vulnerability, CVE-2021-44228, also named #Log4Shell allows for unauthenticated remote code execution and is trivial to exploit. Proof-of-concept code has been published, and we currently observe internet-wide exploit attempts and scanning for vulnerable servers. | The mass scanning activity observed so far has involved attempts at installing several cryptocurrency miners and the Tsunami backdoor.
The Muhstik botnet exploits Drupal vulnerability (CVE-2018-7600), impacting versions 6,7, and 8 of Drupal’s CMS platform.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
"Tsunami, a Linux-based malware used primarily for Distributed Denial of Service (DDoS) attacks, is also a key component of both infection chains."
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
"Tsunami, a Linux-based malware used primarily for Distributed Denial of Service (DDoS) attacks, is also a key component of both infection chains."
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The threat actor replaced its traditional Tsunami backdoor with the stealthier “Sliver” malware.
Further analysis shows that this IP and another Necro C2 IP 193.239.147.224 were also used as C2 by other versions of Gafgyt and Tsunami botnet in early February, which apparently share code with Gafgyt_tor.
Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.
Further, it makes a bunch of references to a TSUNAMI payload which STRIKE hasn’t analyzed, and its role is unknown.
During our analysis we were able to identify a more comprehensive sample of the Tsunami-Framework, a Malware relying on the TOR-Network and Pastebin for command and control. Tsunami has a modular structure, incorporates multiple stealers and deploys two cryptominers.
“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”
32 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on our research, we have discerned that this botnet perpetually scans the entirety of the internet... every IP address undergoes a scan at least once every hour.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
During this campaign, the threat actor focused on compromising unprotected Redis servers... It’s using Redis’s FLUSHALL issue to create a cron job that downloads a setup script. | The default configuration of standard Kubernetes deployments allow anonymous access to kubelet. TeamTNT used this misconfiguration to gain access to exposed Kubernetes instances and run cryptomining malware in the containers. | TeamTNT targeted Docker daemon ports and abused them to install cryptomining malware and DDoS malware... the script uses the exposed port to spawn a new container from the Alpine image.
It then adds a Windows-Defender Exclusion for the “Runtime Broker.exe” and creates a Scheduled Task for secondary persistence.
The mass scanning activity observed so far has involved attempts at installing several cryptocurrency miners and the Tsunami backdoor.
In terms of execution and the download command is a bash implementation used to download scripts and binaries from the C2 server.
When Tsunami is executed, it writes its own path in the “/etc/rc.local” file, making it so that it runs even after reboots.
When Tsunami is executed, it writes its own path in the “/etc/rc.local” file, making it so that it runs even after reboots.
It then adds a Windows-Defender Exclusion for the “Runtime Broker.exe” and creates a Scheduled Task for secondary persistence.
in a fileless malware attack, the malware is loaded into memory and then executed. By executing malicious code directly from memory, attackers can evade detection by static scanners
Most of the Gafgyt and Tsunami samples we captured were not packed... String encoding... Necro also cryptographically protects the string by first performing character substitution and then doing zip compression.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
The scanners used by Keksec are mainly telnet and SSH weak password scan and exploit scan.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
“The core function is still DDoS attacks and scanning”; samples contain scan functions named “ak47Scan” and “ak47telscan.”
Keksec’s malware mainly uses Gafgyt and IRC protocols to send commands.
The IRC protocol is the most widely used protocol in Keksec, and is supported by the Tsunami, Necro and DarkIRC families.
262 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
46 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Mentioned as a dropper referenced in inactive remote-code-execution code within the analyzed TuxBot ecosystem.
Referenced as inherited code/dead-code lineage within TuxBot’s source, indicating reused payload logic from the Tsunami codebase.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.