Skip to content
Malware family

Tsundere

Tsundere is a Node.js-based botnet/RAT malware family targeting Windows systems.

Profile source: Mallory opens in a new tab

Tsundere

Family profile

Tsundere is a Node.js-based botnet/RAT malware family targeting Windows systems. It is delivered via fake or phony MSI installers that install Node.js and legitimate libraries, then execute JavaScript payloads. Reported functionality includes establishing persistence, arbitrary JavaScript code execution on infected hosts, receiving attacker-supplied JavaScript over a WebSocket-based command-and-control channel, filesystem and OS command execution, and data exfiltration. Multiple reports describe its use of blockchain-based C2 resolution: Tsundere or closely related variants use Ethereum/EtherHiding logic to retrieve or refresh C2 server details before validating the address and establishing a WebSocket connection, enabling infrastructure rotation and resilience.

The malware has been referred to as Tsundere and also as DinDoor/Dindoor in some reporting. Check Point assessed DinDoor as a new variant of the MuddyWater-linked Tsundere botnet. JUMPSEC reported that a PowerShell loader delivered Tsundere alongside other TAG-150/CastleRAT platform components, and eSentire/Atos-linked reporting noted Tsundere samples with EtherHiding logic and code commonalities with EtherRAT. Tsundere has been associated in reporting with Iranian state-linked activity, particularly MuddyWater/APT34, although other reporting noted attribution is not conclusive and suggested possible Russian-speaking development based on similarities to a prior Russian npm campaign. One report also stated Tsundere shared infrastructure with the 123 Stealer C2 panel.

Observed infection chains include malicious MSI installers and PowerShell-based loaders. One Hunt.io-referenced case described a malicious file used to establish persistence and deploy Tsundere, and another noted communications with 185.236.25.119:3001; that IP was flagged due to logins to Tsundere botnet panels on ports 80 and 3000. High-confidence behavioral details directly mentioned in the source include Windows targeting, Node.js runtime use, WebSocket C2, blockchain/Ethereum-based C2 discovery, persistence establishment, and execution of arbitrary JavaScript code.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 21, 2026
Last activity
Jul 21, 2026
Feed role
C2
Host form
1 IP / 0 hostnames

Leading locations

  • DE1

Leading providers

  • DEDIK SERVICES LIMITED1

Infrastructure traits

  • Hosting 1

Reported operators

Threat actors

3 named in public reporting
MuddyWater

In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.

OilRig

During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.

GrayBravo

The same PowerShell loader has also been found to deliver a botnet malware referred to as Tsundere (aka Dindoor). According to JUMPSEC, both ChainShell and Tsundere are separate TAG-150 platform components that are deployed along with CastleRAT.

MITRE ATT&CK

Tsundere in ATT&CK

11 distinct techniques

Reporting

Research mentioning Tsundere

Apr 30
The Hacker News

EtherRAT Distribution Spoofing Administrative Tools via GitHub Facades

During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.

Apr 8
The Hacker News

Iran-Linked Hackers Disrupt U.S. Critical Infrastructure by Targeting Internet-Exposed PLCs

The same PowerShell loader has also been found to deliver a botnet malware referred to as Tsundere (aka Dindoor). According to JUMPSEC, both ChainShell and Tsundere are separate TAG-150 platform components that are deployed along with CastleRAT.

Mar 10
Register Security

Cybercrime isn't just a cover for Iran's government goons • The Register

DinDoor ... is a new variant of the MuddyWater-linked Tsundere botnet.

Mar 10
Register Security

Cybercrime isn't just a cover for Iran's government goons

In these intrusions, the group used a previously unseen backdoor called DinDoor, which is a new variant of the MuddyWater-linked Tsundere botnet, according to Check Point.

Mar 4
Huntio

Iranian APT Infrastructure in Focus: Mapping State-Aligned Clusters During Geopolitical Escalation

This IP is identified as high risk in Hunt due to login to Tsundere botnet panels on ports 80 and 3000.

Feb 13
Cloudatg Insights

AI Development & Software Engineering | CloudATG

"... botnet dubbed Tsundere"

Nov 25
Risky Biz Rss

Risky Bulletin: Sha1-Hulud npm worm returns, with destructive behavior

Kaspersky looks at Tsundere, a Node.js-based malware strain that uses npm to host malicious payloads that target Windows systems.

Nov 23
Securityaffairs

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 72

“Blockchain and Node.js abused by Tsundere: an emerging botnet”

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.