logo

TA584 threat actor leverages Tsundere Bot and XWorm for network access

ID: 4b6fe353-aaad-5e46-bbef-d65e6dec5639

STIX ID: report--4b6fe353-aaad-5e46-bbef-d65e6dec5639

Feed Name: Proofpoint Blog

Threat Score
75/100

Date Published: 2026-01-29

Date Updated: 2026-04-28

...
...

TA584, an initial access broker tracked since 2020, has escalated activity by distributing Tsundere Bot and XWorm via phishing emails sent from compromised accounts and mass-mailing services (SendGrid, Amazon SES). The attack chain uses redirectors (e.g., Keitaro), geofencing and IP filters, CAPTCHA gating, and a PowerShell one-liner that loads malware into memory; Tsundere Bot gathers system data, can execute arbitrary code, and retrieves C2 addresses via the Ethereum blockchain. The campaign has expanded geographically into Europe and Australia and is likely designed to provide initial access for ransomware and other criminal operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.