ATT&CKSoftwareTsundere Botnet

Tsundere Botnet

S9034

Malware.View on attack.mitre.org

About this malware

Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor.

A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.

Techniques used17

Procedure examples17

TechniqueProcedure example
T1027.010
Command Obfuscation

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1027.013
Encrypted/Encoded File

Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk.

T1036.005
Match Legitimate Resource Name or Location

Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software.

T1059.001
PowerShell

Tsundere Botnet has been distributed via a PowerShell script.

T1059.007
JavaScript

Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component.

T1071.001
Web Protocols

Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes.

T1082
System Information Discovery

Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information.

T1102.001
Dead Drop Resolver

Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes.

T1105
Ingress Tool Transfer

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.

T1140
Deobfuscate/Decode Files or Information

Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector.

T1195.001
Compromise Software Dependencies and Development Tools

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

T1218.007
Msiexec

Tsundere Botnet has been distributed via an MSI installer.

T1480
Execution Guardrails

Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region.

T1547.001
Registry Run Keys / Startup Folder

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1564.003
Hidden Window

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

View all 17 procedure examples

Groups that use it1

Campaigns0

None recorded.

References4

  1. CAL_MuddyWater_Mar2026 Open source
    Ctrl-Alt-Intel. (2026, March 4). MuddyWater Exposed: Inside an Iranian APT operation . Retrieved April 6, 2026.
  2. Checkpoint_MOISCyberCrime_Mar2026 Open source
    CheckPoint Research. (2026, March 10). Iranian MOIS Actors & the Cyber Crime Connection. Retrieved March 12, 2026.
  3. SOCRadar_MuddyWaterDindoor_Mar2026 Open source
    SOCRadar. (2026, March 9). MuddyWater Uses Dindoor Malware Targeting U.S. Networks. Retrieved March 12, 2026.
  4. SecureListUbiedo_Tsundere_Nov2025 Open source
    Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.