TF-MAL-js.tsundere
📛 Threat Title
Malware family: Tsundere
Description
ThreatFox malware family `js.tsundere`. Printable name: Tsundere. Aliases: DinDoor.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
js.tsundere
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.tsundere
IOC database
- Type
- domain
- Value
js.tsundere- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-js.tsundere
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/js.tsundere
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:cybersecuritynews.com
Tsundere represents a significant shift in botnet tactics, leveraging the power of legitimate Node.js packages and blockchain technology to distribute malware across multiple operating systems. First identified around mid-2025 by Kaspersky GReAT researchers, this botnet demonstrates the evolving sophistication of supply chain attacks.
-
web:cybersixt.com
Kaspersky exposed Tsundere , a Node.js botnet using an Ethereum smart contract for unkillable C2 updates. The system includes a cybercrime marketplace and spreads via fake MSI game installers for RCE.
-
web:intel.mjolnirsecurity.com
Tsundere Malware (also known as Tsundere ) is a malware active since 2024. Emerging malware family . Key characteristics include: emerging threat, anti-analysis techniques, custom C2 protocol.
-
web:malpedia.caad.fkie.fraunhofer.de
Details for the Tsundere malware family including references, samples and yara signatures.
-
web:securelist.com
Kaspersky GReAT experts discovered a new campaign featuring the Tsundere botnet. Node.js-based bots abuse web3 smart contracts and are spread via MSI installers and PowerShell scripts.
-
web:thehackernews.com
Tsundere botnet spreads via MSI and PowerShell installers, using Ethereum-based C2 rotation and game-themed lures to target Windows users.
-
web:www.esentire.com
Learn more about the MuddyWater APT group's deployment of the Tsundere botnet, and get recommendations on how to protect your organization from this cyber threat.
-
web:www.kaspersky.com
The Tsundere botnet employs an increasingly popular approach by using Web3 smart contracts to store its command-and-control (C2) addresses, significantly improving the robustness of its infrastructure. Its C2 panel supports two distribution formats: an MSI installer and a PowerShell script with implants generated automatically.
-
web:www.pcrisk.com
Organizations are urged to adopt multi-layered defenses that include both social engineering mitigation and anomaly detection to identify unusual blockchain interactions originating from corporate networks. Email security remains a frontline defense against phishing campaigns that deliver initial access payloads, such as Tsundere .
-
web:www.proofpoint.com
In general, the malware can be used for information gathering, data exfiltration, lateral movement, and to install additional payloads. Given that Proofpoint has observed this malware used by TA584, researchers assess with high confidence Tsundere Bot malware infections could lead to ransomware.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.