Last seven days
- First activity
- Aug 27, 2026
- Last activity
- Aug 28, 2026
- Feed role
- C2
- Host form
- 0 IP / 2 hostnames
Tsunami, also known as Kaiten, is a long-running UNIX and Linux botnet/backdoor family first observed in 2002.
Profile source: Mallory opens in a new tabTsunami
Tsunami, also known as Kaiten, is a long-running UNIX and Linux botnet/backdoor family first observed in 2002. It primarily compromises Linux servers and Linux-based IoT devices, commonly through weak SSH credentials, exploit-driven propagation, and deployment by other malware. Tsunami typically uses IRC-based command-and-control to receive remote commands, download and execute additional payloads, conduct host and network reconnaissance, and launch distributed denial-of-service attacks including TCP- and UDP-based floods. Variants have implemented SSH scanning and password attacks for propagation, persistence mechanisms, and process-name masquerading. Tsunami has been deployed alongside cryptocurrency miners in numerous campaigns. It has been used by multiple criminal operators and has been repeatedly associated with campaigns attributed to Keksec and TeamTNT, including attacks against exposed servers, routers, container environments, and other internet-facing infrastructure.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Further analysis shows that this IP and another Necro C2 IP 193.239.147.224 were also used as C2 by other versions of Gafgyt and Tsunami botnet in early February, which apparently share code with Gafgyt_tor.
Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.
Further, it makes a bunch of references to a TSUNAMI payload which STRIKE hasn’t analyzed, and its role is unknown.
The elf binary is also executed from memory. It is classified in VirusTotal as Tsunami malware (MD5=48c056a1bf908a424d472f121ccaf44b), something often used in TeamTNT’s other campaigns. Tsunami malware enables a remote attacker to download files and execute shell commands in an infected host.
During our analysis we were able to identify a more comprehensive sample of the Tsunami-Framework, a Malware relying on the TOR-Network and Pastebin for command and control. Tsunami has a modular structure, incorporates multiple stealers and deploys two cryptominers.
“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”
Exploited software
MITRE ATT&CK
Reporting
TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.
Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.