Skip to content

Tsundere

Tsundere is a Node.js-based Windows botnet that uses blockchain-based command-and-control discovery.

Profile source: Mallory opens in a new tab

Tsundere

Family profile

Tsundere is a Node.js-based Windows botnet that uses blockchain-based command-and-control discovery. It is deployed through malicious Windows Installer packages that install a Node.js runtime and legitimate supporting libraries. The malware queries the Ethereum blockchain to obtain and validate a WebSocket command-and-control endpoint, enabling operators to rotate backend infrastructure without updating deployed implants. Tsundere receives and executes arbitrary JavaScript supplied by its command-and-control server, allowing flexible post-compromise actions on infected hosts. Variants and closely related activity have been reported in infrastructure and operations associated with MuddyWater; DinDoor has been assessed as a Tsundere variant. Attribution of the original Tsundere development remains unconfirmed, although reporting has noted possible Russian-speaking developer links.

Capabilities

  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Sep 24, 2026
Last activity
Sep 25, 2026
Feed role
C2
Host form
2 IP / 0 hostnames

Leading locations

  • DE2

Leading providers

  • NEKOBYTE INTERNATIONAL LIMITED2

Infrastructure traits

  • Hosting 2

Reported operators

Threat actors

3 named in public reporting
MuddyWater

“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.

TAG-150

“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.

OilRig

During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.

MITRE ATT&CK

Tsundere in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.