Blockchain and Node.js abused by Tsundere: an emerging botnet
ID: 0fb9d223-bdff-5efe-a1fb-a84535a18dd4
STIX ID: report--0fb9d223-bdff-5efe-a1fb-a84535a18dd4
Feed Name: Securelist by Kaspersky
Kaspersky GReAT discovered and analyzed the Tsundere botnet — a Node.js-based Windows malware family delivered via MSI installers and PowerShell that installs bundled Node.js, uses npm packages (ws, ethers, pm2) for persistence and C2 handling, retrieves WebSocket C2 addresses from an Ethereum smart contract, and exposes a control panel/marketplace with open registration; the report includes file hashes, IPs, wallets, attribution to a likely Russian-speaking actor linked to the 123 Stealer, and notes active infections and low detection rates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
