Tsundere Botnet is a JavaScript-based malware family first publicly documented in 2025 and later linked in multiple reports to activity associated with the Iranian espionage group MuddyWater, although some components have also been attributed to a Russian-speaking actor known as koneko. It is best characterized as a backdoor-oriented malware platform that relies on trusted scripting runtimes rather than conventional compiled implants, using Node.js in earlier reporting and a Deno-based variant known as DinDoor in later activity.
The malware executes obfuscated JavaScript to establish command-and-control, fingerprint infected systems, and retrieve additional payloads. A notable architectural feature is its use of Ethereum smart contracts as a dead-drop mechanism for resolving or rotating command-and-control endpoints, providing resilience against infrastructure takedown. Reported variants have used WebSocket-based communications and have incorporated cloud-storage tooling such as Rclone in operational workflows tied to exfiltration.
Observed delivery has included malicious MSI installers distributed through phishing and drive-by download chains. These installers may silently invoke PowerShell, install or leverage legitimate Node.js or Deno runtimes without requiring elevated privileges, display decoy error dialogs, and execute second-stage JavaScript either from disk or entirely in memory. DinDoor, the Deno-based variant, binds a localhost listener as a mutex, fingerprints the host using basic system attributes, checks command-and-control availability, and then begins beaconing for tasking or payload retrieval.
Tsundere Botnet has been associated with both espionage-oriented intrusions and broader cybercrime-adjacent infrastructure. Reporting has described overlap with shared or multi-tenant backend infrastructure also used by other malware operations, complicating attribution. Targeting linked to related activity has included organizations in the United States and the Middle East, and the malware has appeared alongside MuddyWater tradecraft in campaigns involving reconnaissance, exploitation, tunneling, persistence, and data theft. A Deno-based variant, DinDoor, is widely treated as part of the same malware lineage.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
The file reset.ps1 on MuddyWater's server is not MuddyWater malware. It is a Tsundere Botnet dropper -- a 2.2 MB heavily obfuscated PowerShell script attributed by Kaspersky GReAT to Russian-speaking threat actor "koneko."
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Within the server, we identified that MuddyWater had staged a PowerShell loader, reset.ps1. The PowerShell loader will lead to execution of obfuscated Node.js payloads that appear similar to Tsundere Botnet.
The file reset.ps1 on MuddyWater's server is not MuddyWater malware. It is a Tsundere Botnet dropper -- a 2.2 MB heavily obfuscated PowerShell script attributed by Kaspersky GReAT to Russian-speaking threat actor "koneko."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Within the server, we identified that MuddyWater had staged a PowerShell loader, reset.ps1... The PowerShell loader will lead to execution of obfuscated Node.js payloads.
The PowerShell loader will lead to execution of obfuscated Node.js payloads... Embedded within the PowerShell loader are AES-CBC/PKCS7 encrypted blobs.
Embedded within the PowerShell loader are AES-CBC/PKCS7 encrypted blobs, which are decrypted and written to disk
MITRE ATT&CK Mapping Technique ID Name Evidence T1497.001 System Checks Tsundere CIS locale check (avoids Russian systems)
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2
PersianC2 used standard HTTP polling... This bot communicates over WebSocket to retrieve commands.
MITRE ATT&CK Mapping Technique ID Name Evidence T1102 Web Service Ethereum blockchain for C2 resolution
69 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Botnet family that DinDoor is described as a variant of.
A JavaScript-based remote access tool/botnet using Node.js, described as the broader malware family or umbrella under which DinDoor is tracked as a variant.
Botnet used by MuddyWater as part of MOIS-linked cyber operations.
Botnet malware whose installer hides execution using hidden PowerShell window settings.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.