Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys
ID: eec5be9f-8c76-5cef-b4cf-8fb4e7a23dab
STIX ID: report--eec5be9f-8c76-5cef-b4cf-8fb4e7a23dab
Feed Name: securityonline.info
Proofpoint reports that TA584, an Initial Access Broker, dramatically increased operations in 2025—tripling monthly campaigns—and deployed a new custom malware called Tsundere Bot; the actor uses a stealthy persistence technique (null-terminated Registry entry) that hides an autorun chain (mshta → VBScript → hidden PowerShell) which dynamically fetches payloads, creating a resilient, effectively file-less foothold, and is assessed with high confidence to be embedded in the Russian cybercriminal ecosystem and facilitating ransomware affiliates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
