logo

Initial access hackers switch to Tsundere Bot for ransomware attacks

ID: 396e2c83-865b-5971-8f47-645cff328dc1

STIX ID: report--396e2c83-865b-5971-8f47-645cff328dc1

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2026-01-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Proofpoint observed TA584 shifting to use Tsundere Bot alongside XWorm in expanded, large-scale email-based initial access campaigns: attackers send emails from aged compromised accounts via SendGrid/SES, use TDS redirects, CAPTCHA/ClickFix landing pages and PowerShell loaders to execute obfuscated scripts that load in-memory payloads. Tsundere Bot is a Node.js-based malware with Ethereum-derived C2, data collection and proxying capabilities, and its use by TA584 is assessed as likely to enable ransomware and other post-compromise activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.