A rapidly expanding botnet known as Tsundere is actively targeting Windows users by leveraging fake installers disguised as popular video games such as Valorant, Counter-Strike 2, and Rainbow Six Siege X. The botnet, first observed in mid-2025, executes arbitrary JavaScript code retrieved from a command-and-control (C2) server, with the infrastructure utilizing the Ethereum blockchain for C2 retrieval. Infection vectors include the use of Remote Monitoring and Management (RMM) tools to download malicious MSI installers from compromised websites, as well as PowerShell scripts that deploy Node.js and additional dependencies on victim systems. The malware achieves persistence by installing legitimate Node.js libraries and modifying registry keys to ensure execution upon login.
Kaspersky researchers have identified that the Tsundere botnet's implants are distributed in two main formats: MSI installers and PowerShell scripts. The MSI installer method installs Node.js and the pm2 package to maintain persistence, while the PowerShell variant creates registry entries for the same purpose. The campaign appears to target users seeking pirated versions of popular games, exploiting their interest to propagate the malware. The botnet's infrastructure is actively maintained and poses an ongoing threat, with no definitive evidence yet on all propagation methods, but clear indications of sophisticated social engineering and technical persistence mechanisms.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Kaspersky GReAT publicly disclosed technical details on Tsundere, describing its use of Node.js, AES-256-CBC decryption, pm2 and Run-key persistence, encrypted WebSocket communications, and Ethereum-based C2 discovery. The report also noted links to the 123 Stealer ecosystem, a possible actor handle "koneko," and the presence of a combined marketplace/control panel called "Tsundere Netto" v2.4.4.
During its mid-2025 activity, Tsundere infections were observed masquerading as popular game installers, with artifacts referencing titles such as Valorant, Rainbow Six, and CS2. In at least one case, an RMM tool downloaded a malicious MSI named "pdf.msi" from a compromised website.
Kaspersky reported that the Windows-focused Node.js botnet dubbed Tsundere was discovered around mid-2025 and had been active since then. The malware was seen spreading through fake MSI installers and PowerShell-based infection chains.
In October 2024, a supply-chain campaign published hundreds of malicious npm typosquatting packages. Kaspersky later assessed Tsundere as linked to this earlier activity.
The infrastructure later used by the Tsundere botnet included an Ethereum smart contract created in September 2024 to store or retrieve WebSocket command-and-control server details, enabling resilient C2 rotation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcethehackernews.com
Open sourcesecurelist.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.