logo

Blockchain and Node.js abused by Tsundere: an emerging botnet

ID: 0fb9d223-bdff-5efe-a1fb-a84535a18dd4

STIX ID: report--0fb9d223-bdff-5efe-a1fb-a84535a18dd4

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-11-20

Date Updated: 2026-04-29

Author: Lisandro Ubiedo

...
...

Kaspersky GReAT discovered and analyzed the Tsundere botnet — a Node.js-based Windows malware family delivered via MSI installers and PowerShell that installs bundled Node.js, uses npm packages (ws, ethers, pm2) for persistence and C2 handling, retrieves WebSocket C2 addresses from an Ethereum smart contract, and exposes a control panel/marketplace with open registration; the report includes file hashes, IPs, wallets, attribution to a likely Russian-speaking actor linked to the 123 Stealer, and notes active infections and low detection rates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.