s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-js.tsundere

📛 Threat Title

Malware family: Tsundere

Category: Tsundere First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `js.tsundere`. Printable name: Tsundere. Aliases: DinDoor.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain js.tsundere VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.tsundere

IOC database

Type
domain
Value
js.tsundere
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-js.tsundere

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.tsundere

References (1)

Remediations (10)

  • web:cybersecuritynews.com

    Tsundere represents a significant shift in botnet tactics, leveraging the power of legitimate Node.js packages and blockchain technology to distribute malware across multiple operating systems. First identified around mid-2025 by Kaspersky GReAT researchers, this botnet demonstrates the evolving sophistication of supply chain attacks.

  • web:cybersixt.com

    Kaspersky exposed Tsundere , a Node.js botnet using an Ethereum smart contract for unkillable C2 updates. The system includes a cybercrime marketplace and spreads via fake MSI game installers for RCE.

  • web:intel.mjolnirsecurity.com

    Tsundere Malware (also known as Tsundere ) is a malware active since 2024. Emerging malware family . Key characteristics include: emerging threat, anti-analysis techniques, custom C2 protocol.

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Tsundere malware family including references, samples and yara signatures.

  • web:securelist.com

    Kaspersky GReAT experts discovered a new campaign featuring the Tsundere botnet. Node.js-based bots abuse web3 smart contracts and are spread via MSI installers and PowerShell scripts.

  • web:thehackernews.com

    Tsundere botnet spreads via MSI and PowerShell installers, using Ethereum-based C2 rotation and game-themed lures to target Windows users.

  • web:www.esentire.com

    Learn more about the MuddyWater APT group's deployment of the Tsundere botnet, and get recommendations on how to protect your organization from this cyber threat.

  • web:www.kaspersky.com

    The Tsundere botnet employs an increasingly popular approach by using Web3 smart contracts to store its command-and-control (C2) addresses, significantly improving the robustness of its infrastructure. Its C2 panel supports two distribution formats: an MSI installer and a PowerShell script with implants generated automatically.

  • web:www.pcrisk.com

    Organizations are urged to adopt multi-layered defenses that include both social engineering mitigation and anomaly detection to identify unusual blockchain interactions originating from corporate networks. Email security remains a frontline defense against phishing campaigns that deliver initial access payloads, such as Tsundere .

  • web:www.proofpoint.com

    In general, the malware can be used for information gathering, data exfiltration, lateral movement, and to install additional payloads. Given that Proofpoint has observed this malware used by TA584, researchers assess with high confidence Tsundere Bot malware infections could lead to ransomware.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.