Tsundere is a Node.js-based Windows malware family described as a botnet or backdoor platform that executes arbitrary JavaScript received from its command-and-control infrastructure. It is associated in multiple investigations with blockchain-based command-and-control discovery, using Ethereum-hosted data or smart-contract logic to resolve or refresh live server details before establishing WebSocket communications. This design provides resilience against infrastructure disruption and enables operators to rapidly rotate command-and-control endpoints.
Observed Tsundere infections have been delivered through fraudulent MSI installers that deploy Node.js together with legitimate libraries and then launch the malicious JavaScript components. The malware validates resolved command-and-control information, opens a WebSocket channel, and executes attacker-supplied JavaScript on the infected host, giving operators flexible post-compromise control. Reported variants and closely related components have also incorporated persistence logic and EtherHiding-style command-and-control resolution.
Tsundere has been linked by several researchers to activity involving Iranian state-aligned MuddyWater, including a variant referred to as DinDoor, while other reporting notes similarities to Russian-speaking criminal tradecraft and shared infrastructure patterns with other malware. Attribution of original development remains uncertain, but the malware has been observed in operations targeting Windows environments and has appeared alongside other malware-as-a-service or criminal ecosystem tooling. High-confidence reporting supports Windows targeting, JavaScript-based remote execution, persistence in some deployments, and blockchain-assisted command-and-control resilience.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.
Central to the operations is a PowerShell deployer ("reset.ps1") that deploys a previously undocumented JavaScript-based malware called ChainShell...
Central to the operations is a PowerShell deployer ("reset.ps1") that deploys a previously undocumented JavaScript-based malware called ChainShell, which then contacts a smart contract on the Ethereum blockchain to retrieve a C2 address and use it to fetch next-stage JavaScript code for execution on compromised hosts.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
Other indicator types observed in public reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet malware noted here for integrating the EtherHiding C2 resolution logic and sharing extensive code commonalities with EtherRAT.
Botnet malware delivered by the same PowerShell loader and deployed alongside CastleRAT as part of TAG-150 platform components.
A Deno-based JavaScript RAT variant within the TAG-150 platform, deployed alongside CastleRAT by the same operator.
Botnet family linked to MuddyWater; referenced as the lineage for the DinDoor backdoor variant.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.