Last seven days
- First activity
- Jul 21, 2026
- Last activity
- Jul 21, 2026
- Feed role
- C2
- Host form
- 1 IP / 0 hostnames
Tsundere is a Node.js-based botnet/RAT malware family targeting Windows systems.
Profile source: Mallory opens in a new tabTsundere
Tsundere is a Node.js-based botnet/RAT malware family targeting Windows systems. It is delivered via fake or phony MSI installers that install Node.js and legitimate libraries, then execute JavaScript payloads. Reported functionality includes establishing persistence, arbitrary JavaScript code execution on infected hosts, receiving attacker-supplied JavaScript over a WebSocket-based command-and-control channel, filesystem and OS command execution, and data exfiltration. Multiple reports describe its use of blockchain-based C2 resolution: Tsundere or closely related variants use Ethereum/EtherHiding logic to retrieve or refresh C2 server details before validating the address and establishing a WebSocket connection, enabling infrastructure rotation and resilience.
The malware has been referred to as Tsundere and also as DinDoor/Dindoor in some reporting. Check Point assessed DinDoor as a new variant of the MuddyWater-linked Tsundere botnet. JUMPSEC reported that a PowerShell loader delivered Tsundere alongside other TAG-150/CastleRAT platform components, and eSentire/Atos-linked reporting noted Tsundere samples with EtherHiding logic and code commonalities with EtherRAT. Tsundere has been associated in reporting with Iranian state-linked activity, particularly MuddyWater/APT34, although other reporting noted attribution is not conclusive and suggested possible Russian-speaking development based on similarities to a prior Russian npm campaign. One report also stated Tsundere shared infrastructure with the 123 Stealer C2 panel.
Observed infection chains include malicious MSI installers and PowerShell-based loaders. One Hunt.io-referenced case described a malicious file used to establish persistence and deploy Tsundere, and another noted communications with 185.236.25.119:3001; that IP was flagged due to logins to Tsundere botnet panels on ports 80 and 3000. High-confidence behavioral details directly mentioned in the source include Windows targeting, Node.js runtime use, WebSocket C2, blockchain/Ethereum-based C2 discovery, persistence establishment, and execution of arbitrary JavaScript code.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.
During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.
The same PowerShell loader has also been found to deliver a botnet malware referred to as Tsundere (aka Dindoor). According to JUMPSEC, both ChainShell and Tsundere are separate TAG-150 platform components that are deployed along with CastleRAT.
MITRE ATT&CK
Reporting
During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.
The same PowerShell loader has also been found to deliver a botnet malware referred to as Tsundere (aka Dindoor). According to JUMPSEC, both ChainShell and Tsundere are separate TAG-150 platform components that are deployed along with CastleRAT.
DinDoor ... is a new variant of the MuddyWater-linked Tsundere botnet.
In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.
This IP is identified as high risk in Hunt due to login to Tsundere botnet panels on ports 80 and 3000.
"... botnet dubbed Tsundere"
Kaspersky looks at Tsundere, a Node.js-based malware strain that uses npm to host malicious payloads that target Windows systems.
“Blockchain and Node.js abused by Tsundere: an emerging botnet”
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.