logo

TA584 Actors Leveraging ClickFix Social Engineering to Deliver Tsundere Bot Malware

ID: 28984cee-de81-57ed-b23d-fc4aa80b488d

STIX ID: report--28984cee-de81-57ed-b23d-fc4aa80b488d

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

TA584 has been observed distributing a new Node.js-based malware called Tsundere Bot via sophisticated phishing lures and the ClickFix social-engineering flow; the malware uses EtherHiding (retrieving configuration from Ethereum smart contracts), enforces geofencing/anti-analysis checks, can lead to ransomware deployment, and communicates with a reported C2 at 193.17.183.126:3001.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.