Last seven days
- First activity
- Sep 24, 2026
- Last activity
- Sep 25, 2026
- Feed role
- C2
- Host form
- 2 IP / 0 hostnames
Tsundere is a Node.js-based Windows botnet that uses blockchain-based command-and-control discovery.
Profile source: Mallory opens in a new tabTsundere
Tsundere is a Node.js-based Windows botnet that uses blockchain-based command-and-control discovery. It is deployed through malicious Windows Installer packages that install a Node.js runtime and legitimate supporting libraries. The malware queries the Ethereum blockchain to obtain and validate a WebSocket command-and-control endpoint, enabling operators to rotate backend infrastructure without updating deployed implants. Tsundere receives and executes arbitrary JavaScript supplied by its command-and-control server, allowing flexible post-compromise actions on infected hosts. Variants and closely related activity have been reported in infrastructure and operations associated with MuddyWater; DinDoor has been assessed as a Tsundere variant. Attribution of the original Tsundere development remains unconfirmed, although reporting has noted possible Russian-speaking developer links.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.