TsunamiKit is a multi-stage malware toolkit documented by ESET and associated in the reporting with the North Korea-aligned DeceptiveDevelopment / Contagious Interview activity cluster, which overlaps with broader Lazarus-linked operations. It has been delivered as a follow-on payload by InvisibleFerret, and reporting also states it has been fetched from Pastebin in some infection chains. The surrounding campaigns target software developers, software engineers, and DevOps/DevSecOps personnel across Windows, Linux, and macOS, with particular emphasis on cryptocurrency, Web3, and related technical roles, typically via fake recruiter and job interview lures, trojanized coding challenges, GitHub-like repositories, ClickFix-style prompts, and abuse of legitimate JSON storage services such as JsonSilo, JsonKeeper, and Npoint for staging payloads.
Based on the provided content, TsunamiKit is designed for information theft and cryptocurrency theft and performs host fingerprinting, data stealing, and lateral movement. It is described as carrying a Base64-encoded URL payload and sending encoded data to .onion infrastructure through Tor. ESET describes the toolkit as centered around a .NET backdoor / spyware payload and composed of multiple Python and .NET droppers and installers, including components named TsunamiLoader, TsunamiInjector, TsunamiHardener, TsunamiInstaller, TsunamiClientInstaller, and TsunamiClient. Reported functionality includes persistence establishment, Microsoft Defender exclusions, deployment of a Tor proxy, download-and-execute behavior, and dropping cryptocurrency miners including XMRig and NBMiner. The final payload is described as a complex .NET spyware component.
The content states TsunamiKit was observed in a modified InvisibleFerret browser-data stealer module beginning in November 2024. ESET also reported TsunamiKit-related samples on VirusTotal dating back to December 2021, indicating the toolkit predates DeceptiveDevelopment’s known activity and is likely a modification of a pre-existing dark web project rather than a new malware family created by the operators. Reported related infrastructure includes Pastebin profiles and an onion address, and campaign reporting ties TsunamiKit deployment to broader BeaverTail and InvisibleFerret infection chains used in North Korean fake-interview operations.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This module contains a completely new toolkit named TsunamiKit by ESET, based on the developer's use of 'Tsunami' in the names of all of its components. It's also designed to steal information and cryptocurrency, and its execution chain includes multiple stages of droppers and installers written in Python and .NET, plus a Tor network proxy, coinminers, and the final .NET spyware payload.
...previously undocumented backdoor called AkdoorTea, along with tools like TsunamiKit and Tropidoor.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
Dosyalar içerisinde base64 ile encode edilmiş malware tarzında bir payload var... TsunamiKit, base64 ile encode edilmiş bir url yükü taşıyor
safe Json Storage servisleri olarak görülen “JsonSilo, JsonKeeper, Npoint” gibi alanları kullanarak meşru bir trafik gibi görünerek saldırıyı devam ettirdikleri... Aslında burada HTTP trafiği izlenerek olay çözümlenmekte
its execution chain includes multiple stages of droppers and installers written in Python and .NET, plus a Tor network proxy, coinminers, and the final .NET spyware payload.
TsunamiKit, base64 ile encode edilmiş bir url yükü taşıyor ve kendisini “.onion” adreslerine gönderiyor.
71 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool appearing in DPRK-linked campaigns, including Contagious Interview-related reporting.
Tool referenced as part of the same DPRK-linked developer-targeting campaign; no further details in excerpt.
Additional tool fetched by InvisibleFerret; used to profile systems, steal data, and retrieve additional payloads (including from a Tor .onion server, per earlier research).
Veri hırsızlığı, sistem fingerprinting ve lateral movement işlevleri olan malware; ayrıca base64 kodlu URL yükü taşıdığı ve .onion adreslerine veri/iletişim gönderdiği belirtiliyor.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.