Tsunami, also known in some contexts as Kaiten or TsunamiKit, is a long-running Linux malware family best known as an IRC-controlled botnet and backdoor used primarily for distributed denial-of-service attacks. It has been observed as an ELF payload on Linux systems, including servers, embedded devices, and IoT-class targets, and has appeared both as a standalone bot and as a secondary payload dropped after exploitation of exposed services or remote code execution vulnerabilities.
The malware’s core behavior centers on joining attacker-controlled IRC infrastructure to receive commands for remote control and attack execution. High-confidence reporting consistently associates Tsunami with DDoS functionality and backdoor capabilities, making it useful both for botnet operations and for maintaining post-compromise access. It has also been deployed alongside cryptocurrency miners in opportunistic Linux intrusion campaigns, especially in cloud and container-focused operations.
Tsunami has been linked to multiple threat ecosystems rather than a single operator. It has appeared in TeamTNT-associated cloud attacks, in Linux botnet activity observed through SSH honeypots, in exploitation waves following major internet-facing vulnerabilities such as Shellshock and Log4Shell, and as a payload installed by malware loaders and spreaders used by cryptomining groups. Variants and derivative families have also been documented: Muhstik has been described as a Tsunami variant incorporating Mirai code, and Remaiten was reported to combine features from Tsunami and LizardStresser/Torlus.
Operationally, Tsunami is most strongly characterized as a Linux bot/backdoor with IRC-based command and control, DDoS attack support, and general remote command execution capability. It is commonly used after initial compromise rather than as a self-contained initial access mechanism, although it may be delivered through exploitation chains, brute-force-driven Linux botnet activity, or follow-on payload deployment in broader campaigns.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
6 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
ClamAV signatures include "Unix.Malware.Tsunami" in the list of malware activity associated with ongoing exploitation campaigns.
"Tsunami, a Linux-based malware used primarily for Distributed Denial of Service (DDoS) attacks, is also a key component of both infection chains."
Currently, there are few samples and the following vulnerabilities are exploited. CVE_2020_14882
"Tsunami, a Linux-based malware used primarily for Distributed Denial of Service (DDoS) attacks, is also a key component of both infection chains."
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A crypto miner and a backdoor, the latter of which uses the Tsunami virus as its weapon of choice, are included in the attack’s secondary payload.
“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”
Listed in several Lazarus/BeaverTail/InvisibleFerret related items as “tsunami,” including “Lazarus Tsunami InvisibleFerret.”
10 distinct techniques documented for this family, organized by ATT&CK tactic.
Authorities claim they’ve gained control of Rapper Bot and stopped attacks emanating from what they described as “among the most powerful DDoS botnets to have ever existed.” ... Rapper Bot allegedly conducted more than 370,000 attacks... Officials said Rapper Bot regularly conducted DDoS attacks measured between two to three terabits per second, adding that Rapper Bot’s largest attack may have exceeded six terabits per second.
8 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a dropper referenced in inactive remote-code-execution code within the analyzed TuxBot ecosystem.
Referenced as inherited code/dead-code lineage within TuxBot’s source, indicating reused payload logic from the Tsunami codebase.
A named malware family included in the report tags related to Linux SSH server threats.
Referenced as a Linux botnet family known for using altered UPX magic bytes in packed ELF32 binaries.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.