logo

The Cyber Nexus: Iranian Group ‘Muddy Water’ Caught Deploying Russian ‘Tsundere’ Botnet via EtherHiding

ID: 636c3e8e-8cc6-527a-87c9-34e3fee75997

STIX ID: report--636c3e8e-8cc6-527a-87c9-34e3fee75997

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-03-18

Date Updated: 2026-04-23

Author: Ddos

...
...

eSentire’s Threat Response Unit reports that Iranian state-aligned group Muddy Water has deployed the Tsundere botnet — a likely Russian-developed Malware-as-a-Service — which leverages an "EtherHiding" technique storing C2 addresses in Ethereum smart contracts to evade takedown; the malware includes CIS-country avoidance checks and JavaScript obfuscation similar to North Korean APTs, indicating high sophistication and national-security implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.