Skip to content

Tsunami

Tsunami, also known as Kaiten, is a long-running UNIX and Linux botnet/backdoor family first observed in 2002.

Profile source: Mallory opens in a new tab

Tsunami

Family profile

Tsunami, also known as Kaiten, is a long-running UNIX and Linux botnet/backdoor family first observed in 2002. It primarily compromises Linux servers and Linux-based IoT devices, commonly through weak SSH credentials, exploit-driven propagation, and deployment by other malware. Tsunami typically uses IRC-based command-and-control to receive remote commands, download and execute additional payloads, conduct host and network reconnaissance, and launch distributed denial-of-service attacks including TCP- and UDP-based floods. Variants have implemented SSH scanning and password attacks for propagation, persistence mechanisms, and process-name masquerading. Tsunami has been deployed alongside cryptocurrency miners in numerous campaigns. It has been used by multiple criminal operators and has been repeatedly associated with campaigns attributed to Keksec and TeamTNT, including attacks against exposed servers, routers, container environments, and other internet-facing infrastructure.

Capabilities

  • Brute Force
  • Ddos
  • Defense Evasion
  • Lateral Movement
  • Persistence
  • Post Exploitation
  • Reconnaissance
  • Scanning

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 27, 2026
Last activity
Aug 28, 2026
Feed role
C2
Host form
0 IP / 2 hostnames

Leading locations

  • US2

Leading providers

  • Google LLC2

Infrastructure traits

  • Anycast 2
  • Hosting 2

Reported operators

Threat actors

6 named in public reporting
keksec group

Further analysis shows that this IP and another Necro C2 IP 193.239.147.224 were also used as C2 by other versions of Gafgyt and Tsunami botnet in early February, which apparently share code with Gafgyt_tor.

Keksec

Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.

Lazarus

Further, it makes a bunch of references to a TSUNAMI payload which STRIKE hasn’t analyzed, and its role is unknown.

TeamTNT

The elf binary is also executed from memory. It is classified in VirusTotal as Tsunami malware (MD5=48c056a1bf908a424d472f121ccaf44b), something often used in TeamTNT’s other campaigns. Tsunami malware enables a remote attacker to download files and execute shell commands in an infected host.

Contagious Interview

During our analysis we were able to identify a more comprehensive sample of the Tsunami-Framework, a Malware relying on the TOR-Network and Pastebin for command and control. Tsunami has a modular structure, incorporates multiple stealers and deploys two cryptominers.

8220 Gang

“bi.64 -> Tsunami… Tsunami is a popular botnet that controls and communicates through the IRC protocol. Its main functions include remote control and DDoS attacks.”

Exploited software

Vulnerabilities linked to Tsunami

9 CVEs

MITRE ATT&CK

Tsunami in ATT&CK

53 distinct techniques

Techniques

53 techniques
T1046 Network Service Discovery T1059 Command and Scripting Interpreter T1203 Exploitation for Client Execution T1105 Ingress Tool Transfer T1190 Exploit Public-Facing Application T1498 Network Denial of Service T1110 Brute Force T1040 Network Sniffing T1071.001 Web Protocols T1036 Masquerading T1027.002 Software Packing T1595.002 Vulnerability Scanning T1027 Obfuscated Files or Information T1071 Application Layer Protocol T1082 System Information Discovery T1083 File and Directory Discovery T1059.004 Unix Shell T1204 User Execution T1055 Process Injection T1219 Remote Access Tools T1595 Active Scanning T1611 Escape to Host T1499 Endpoint Denial of Service T1020 Automated Exfiltration T1584.005 Botnet T1543 Create or Modify System Process T1539 Steal Web Session Cookie T1053.005 Scheduled Task T1037 Boot or Logon Initialization Scripts T1608 Stage Capabilities T1555 Credentials from Password Stores T1566 Phishing T1562.001 Disable or Modify Tools T1053.003 Cron T1496.001 Compute Hijacking T1195 Supply Chain Compromise T1589.001 Credentials T1110.001 Password Guessing T1613 Container and Resource Discovery T1056 Input Capture T1053.007 Container Orchestration Job T1562.004 Disable or Modify System Firewall T1547 Boot or Logon Autostart Execution T1587.001 Malware T1574.006 Dynamic Linker Hijacking T1014 Rootkit T1620 Reflective Code Loading T1496 Resource Hijacking T1070.004 File Deletion T1041 Exfiltration Over C2 Channel T1570 Lateral Tool Transfer T1222 File and Directory Permissions Modification T1588.002 Tool

Reporting

Research mentioning Tsunami

Jul 31
Sysdig

Threat news: TeamTNT stealing credentials using EC2 Instance Metadata | Sysdig

TeamTNT continued to evolve from a Linux-focused cryptojacking group into a broad cloud threat actor targeting exposed Redis, Docker, Kubernetes, Jupyter, Hadoop, PostgreSQL, Tomcat, Nginx, SSH, and other internet-facing services. Researchers tied the group to worm-like campaigns that rapidly scanned for vulnerable hosts, deployed XMRig miners, dropped Tsunami-based IRC bots including DDoS-capable variants, and used malicious container images on Docker Hub to spread payloads at scale. One TeamTNT-linked Docker Hub account reportedly served images pulled more than 150,000 times, while later campaigns showed the group abusing public registries, compromised accounts, and cloud-native tooling to infect newly exposed systems and report them back to command-and-control infrastructure. Across these operations, TeamTNT consistently paired monetization with aggressive credential theft and stealth. Investigations found the group harvesting AWS, Azure, GCP, Kubernetes, Git, NPM, Grafana, database, and storage secrets; stealing SSH keys and host data; and using tools such as Weave Scope, Peirates, BotB, MimiPenguin, Mimipy, tmate, and Gsocket to expand access and persistence. Analysts also documented detection evasion through log wiping, process hiding, LD_PRELOAD userland rootkits, the Diamorphine kernel rootkit, privileged containers with restart policies, and even disabling runc to lock out rival attackers, underscoring TeamTNT’s shift from opportunistic mining to sustained compromise of cloud and container environments.

Jul 21
Security Online Info

TuxBot v3 Evolution: LLM-Built IoT Botnet Exposed

Palo Alto Networks Unit 42 reported on TuxBot v3 Evolution, a previously undocumented modular IoT botnet framework that can infect devices, maintain persistence, communicate over encrypted command-and-control channels, and launch distributed denial-of-service attacks across 17 CPU architectures. Researchers recovered the botnet’s source code, compiled binaries, Docker-based test infrastructure, and 254 DDoS benchmark reports, showing active development and testing into early 2026. The malware’s working capabilities include Telnet brute-forcing with 1,496 credentials, SSH, HTTP, and ADB scanning, plus fallback mechanisms such as a domain generation algorithm and peer-to-peer gossiping. The report said the framework appears to have been developed with heavy LLM assistance, which introduced several implementation flaws, including a broken XOR string table, a nonfunctional exploit virtual machine, and a fake Argon2id routine that actually behaves like repeated SHA-256 hashing similar to PBKDF2. Despite those defects, Unit 42 assessed the botnet as operationally dangerous because its core infection and DDoS functions work, and the bugs are relatively easy to correct. Telemetry linked the malware to active infrastructure including a command-and-control server at 209.182.237[.]133 and a dropper at 185.10.68[.]127, with reported ties to the Keksec/Kaitori and AISURU ecosystems.

Jul 16
Scworld

New TuxBot v3 Evolution IoT botnet framework shows signs of AI development | brief | SC Media

Jul 16
Security Affairs

TuxBot v3: The IoT Botnet Built With AI - Bugs, Disclaimers and All

Jul 16
Cyber Security News

New TuxBot v3 IoT Botnet Uses LLM-Generated Code to Hijack Devices and Launch DDoS Attacks

Jul 16
Cysecurity News

AI-Assisted TuxBot v3 Evolution Botnet Targets IoT Devices With Modular Multi-Channel Attack Framework - CySecurity News - Latest Information Security and Hacking Incidents

Jul 15
The Hacker News

TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development

Jul 15
Palo Alto Networks Unit 42

TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.