Skip to content
Malware family Linux

Tsunami

Tsunami, also known in some contexts as Kaiten or TsunamiKit, is a long-running Linux malware family best known as an IRC-controlled botnet and backdoor used primarily for distributed denial-of-service attacks.

Profile source: Mallory opens in a new tab

Tsunami

Family profile

Tsunami, also known in some contexts as Kaiten or TsunamiKit, is a long-running Linux malware family best known as an IRC-controlled botnet and backdoor used primarily for distributed denial-of-service attacks. It has been observed as an ELF payload on Linux systems, including servers, embedded devices, and IoT-class targets, and has appeared both as a standalone bot and as a secondary payload dropped after exploitation of exposed services or remote code execution vulnerabilities.

The malware’s core behavior centers on joining attacker-controlled IRC infrastructure to receive commands for remote control and attack execution. High-confidence reporting consistently associates Tsunami with DDoS functionality and backdoor capabilities, making it useful both for botnet operations and for maintaining post-compromise access. It has also been deployed alongside cryptocurrency miners in opportunistic Linux intrusion campaigns, especially in cloud and container-focused operations.

Tsunami has been linked to multiple threat ecosystems rather than a single operator. It has appeared in TeamTNT-associated cloud attacks, in Linux botnet activity observed through SSH honeypots, in exploitation waves following major internet-facing vulnerabilities such as Shellshock and Log4Shell, and as a payload installed by malware loaders and spreaders used by cryptomining groups. Variants and derivative families have also been documented: Muhstik has been described as a Tsunami variant incorporating Mirai code, and Remaiten was reported to combine features from Tsunami and LizardStresser/Torlus.

Operationally, Tsunami is most strongly characterized as a Linux bot/backdoor with IRC-based command and control, DDoS attack support, and general remote command execution capability. It is commonly used after initial compromise rather than as a self-contained initial access mechanism, although it may be delivered through exploitation chains, brute-force-driven Linux botnet activity, or follow-on payload deployment in broader campaigns.

Capabilities

  • Ddos
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 18, 2026
Last activity
Jul 18, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • FR1
  • SG1

Leading providers

  • Hostinger International Limited1
  • velia.net Internetdienste GmbH1

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

4 named in public reporting
TeamTNT

A crypto miner and a backdoor, the latter of which uses the Tsunami virus as its weapon of choice, are included in the attack’s secondary payload.

8220 Gang

“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”

8220

“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”

Contagious Interview

Listed in several Lazarus/BeaverTail/InvisibleFerret related items as “tsunami,” including “Lazarus Tsunami InvisibleFerret.”

Exploited software

Vulnerabilities linked to Tsunami

6 CVEs

MITRE ATT&CK

Tsunami in ATT&CK

10 distinct techniques

Reporting

Research mentioning Tsunami

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

IPv4 address 188.166.2.226 Tsunami dropper in inactive RCE code

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

One additional artifact sits in the source code. The RCE scanning engine contains a hard-coded payload that downloads from hxxp[:]//188.166.2[.]226/OwO/Tsunami.x86 with the user-agent r00ts3c-owned-you.

Apr 12
Ahnlab Asec

Q1 2026 Malware Statistics Report for Linux SSH Servers - ASEC

Tags: BruteForceAttack ... Gafgyt ... Honeypot ... Linux ... Mirai ... P2PInfect ... Prometei ... Proxy ... ShellBot ... Trojan ... Tsunami ...

Apr 3
Breakglass Intel

ELF Modified UPX - Breakglass Intelligence Report - Breakglass Intelligence - Breakglass Intelligence

The JPCERT/CC rule upx_antiunpack_elf32 is the most significant — it specifically detects UPX-packed ELF32 binaries where the magic bytes have been altered, which is a known technique used by Linux botnets (Mirai, Gafgyt, Tsunami).

Feb 11
Security Affairs

SSHStalker botnet targets Linux servers with legacy exploits and SSH scanning

SSHStalker relies on IRC as its command-and-control backbone, using multiple C-based bots, Perl scripts, and known malware families like Tsunami and Keiten.

Feb 9
Flareio

Old-School IRC, New Victims: Inside the Newly Discovered SSHStalker Linux Botnet - Flare | Threat Exposure Management | Unmatched Visibility into Cybercrime

“SSHStalker relies on classic, “old-school” IRC botnet mechanics… + Tsunami malware + Keiten malware…”

Feb 3
Red Asgard

Hunting Lazarus Part IV: Real Blood on the Wire ? Red Asgard Blog

"YARA Rules: ... lazarus_tsunami_backdoor Tsunami/XMRig payload indicators"

Jan 21
Scworld

VS Code projects weaponized in developer-targeted Contagious Interview campaign | SC Media

...the exploitation of a VS Code task configuration to facilitate the eventual deployment of the Tsunami backdoor, also known as TsunamiKit, and the XMRig cryptominer.

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.