The Cyber Nexus: Iranian Group ‘Muddy Water’ Caught Deploying Russian ‘Tsundere’ Botnet via EtherHiding
ID: 636c3e8e-8cc6-527a-87c9-34e3fee75997
STIX ID: report--636c3e8e-8cc6-527a-87c9-34e3fee75997
Feed Name: securityonline.info
Threat Score
eSentire’s Threat Response Unit reports that Iranian state-aligned group Muddy Water has deployed the Tsundere botnet — a likely Russian-developed Malware-as-a-Service — which leverages an "EtherHiding" technique storing C2 addresses in Ethereum smart contracts to evade takedown; the malware includes CIS-country avoidance checks and JavaScript obfuscation similar to North Korean APTs, indicating high sophistication and national-security implications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
