logo

Hidden in Plain Sight: TA584 Deploys “Tsundere Bot” & Invisible Registry Keys

ID: eec5be9f-8c76-5cef-b4cf-8fb4e7a23dab

STIX ID: report--eec5be9f-8c76-5cef-b4cf-8fb4e7a23dab

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-02

Date Updated: 2026-04-23

Author: Ddos

...
...

Proofpoint reports that TA584, an Initial Access Broker, dramatically increased operations in 2025—tripling monthly campaigns—and deployed a new custom malware called Tsundere Bot; the actor uses a stealthy persistence technique (null-terminated Registry entry) that hides an autorun chain (mshta → VBScript → hidden PowerShell) which dynamically fetches payloads, creating a resilient, effectively file-less foothold, and is assessed with high confidence to be embedded in the Russian cybercriminal ecosystem and facilitating ransomware affiliates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.