Skip to content

Tsundere

Tsundere is a Node.js-based Windows malware family described as a botnet or backdoor platform that executes arbitrary JavaScript received from its command-and-control infrastructure.

Profile source: Mallory opens in a new tab

Tsundere

Family profile

Tsundere is a Node.js-based Windows malware family described as a botnet or backdoor platform that executes arbitrary JavaScript received from its command-and-control infrastructure. It is associated in multiple investigations with blockchain-based command-and-control discovery, using Ethereum-hosted data or smart-contract logic to resolve or refresh live server details before establishing WebSocket communications. This design provides resilience against infrastructure disruption and enables operators to rapidly rotate command-and-control endpoints.

Observed Tsundere infections have been delivered through fraudulent MSI installers that deploy Node.js together with legitimate libraries and then launch the malicious JavaScript components. The malware validates resolved command-and-control information, opens a WebSocket channel, and executes attacker-supplied JavaScript on the infected host, giving operators flexible post-compromise control. Reported variants and closely related components have also incorporated persistence logic and EtherHiding-style command-and-control resolution.

Tsundere has been linked by several researchers to activity involving Iranian state-aligned MuddyWater, including a variant referred to as DinDoor, while other reporting notes similarities to Russian-speaking criminal tradecraft and shared infrastructure patterns with other malware. Attribution of original development remains uncertain, but the malware has been observed in operations targeting Windows environments and has appeared alongside other malware-as-a-service or criminal ecosystem tooling. High-confidence reporting supports Windows targeting, JavaScript-based remote execution, persistence in some deployments, and blockchain-assisted command-and-control resilience.

Capabilities

  • Defense Evasion
  • Persistence
  • Post Exploitation

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 12, 2026
Last activity
Aug 15, 2026
Feed role
C2
Host form
3 IP / 0 hostnames

Leading locations

  • DE2
  • US1

Leading providers

  • DEDIK SERVICES LIMITED3

Infrastructure traits

  • Hosting 3

Reported operators

Threat actors

3 named in public reporting
MuddyWater

“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.

TAG-150

“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.

OilRig

During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.

MITRE ATT&CK

Tsundere in ATT&CK

11 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.