Last seven days
- First activity
- Jul 18, 2026
- Last activity
- Jul 18, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Tsunami, also known in some contexts as Kaiten or TsunamiKit, is a long-running Linux malware family best known as an IRC-controlled botnet and backdoor used primarily for distributed denial-of-service attacks.
Profile source: Mallory opens in a new tabTsunami
Tsunami, also known in some contexts as Kaiten or TsunamiKit, is a long-running Linux malware family best known as an IRC-controlled botnet and backdoor used primarily for distributed denial-of-service attacks. It has been observed as an ELF payload on Linux systems, including servers, embedded devices, and IoT-class targets, and has appeared both as a standalone bot and as a secondary payload dropped after exploitation of exposed services or remote code execution vulnerabilities.
The malware’s core behavior centers on joining attacker-controlled IRC infrastructure to receive commands for remote control and attack execution. High-confidence reporting consistently associates Tsunami with DDoS functionality and backdoor capabilities, making it useful both for botnet operations and for maintaining post-compromise access. It has also been deployed alongside cryptocurrency miners in opportunistic Linux intrusion campaigns, especially in cloud and container-focused operations.
Tsunami has been linked to multiple threat ecosystems rather than a single operator. It has appeared in TeamTNT-associated cloud attacks, in Linux botnet activity observed through SSH honeypots, in exploitation waves following major internet-facing vulnerabilities such as Shellshock and Log4Shell, and as a payload installed by malware loaders and spreaders used by cryptomining groups. Variants and derivative families have also been documented: Muhstik has been described as a Tsunami variant incorporating Mirai code, and Remaiten was reported to combine features from Tsunami and LizardStresser/Torlus.
Operationally, Tsunami is most strongly characterized as a Linux bot/backdoor with IRC-based command and control, DDoS attack support, and general remote command execution capability. It is commonly used after initial compromise rather than as a self-contained initial access mechanism, although it may be delivered through exploitation chains, brute-force-driven Linux botnet activity, or follow-on payload deployment in broader campaigns.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
A crypto miner and a backdoor, the latter of which uses the Tsunami virus as its weapon of choice, are included in the attack’s secondary payload.
“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”
“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”
Listed in several Lazarus/BeaverTail/InvisibleFerret related items as “tsunami,” including “Lazarus Tsunami InvisibleFerret.”
Exploited software
MITRE ATT&CK
Reporting
IPv4 address 188.166.2.226 Tsunami dropper in inactive RCE code
One additional artifact sits in the source code. The RCE scanning engine contains a hard-coded payload that downloads from hxxp[:]//188.166.2[.]226/OwO/Tsunami.x86 with the user-agent r00ts3c-owned-you.
Tags: BruteForceAttack ... Gafgyt ... Honeypot ... Linux ... Mirai ... P2PInfect ... Prometei ... Proxy ... ShellBot ... Trojan ... Tsunami ...
The JPCERT/CC rule upx_antiunpack_elf32 is the most significant — it specifically detects UPX-packed ELF32 binaries where the magic bytes have been altered, which is a known technique used by Linux botnets (Mirai, Gafgyt, Tsunami).
SSHStalker relies on IRC as its command-and-control backbone, using multiple C-based bots, Perl scripts, and known malware families like Tsunami and Keiten.
“SSHStalker relies on classic, “old-school” IRC botnet mechanics… + Tsunami malware + Keiten malware…”
"YARA Rules: ... lazarus_tsunami_backdoor Tsunami/XMRig payload indicators"
...the exploitation of a VS Code task configuration to facilitate the eventual deployment of the Tsunami backdoor, also known as TsunamiKit, and the XMRig cryptominer.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.