Last seven days
- First activity
- Aug 12, 2026
- Last activity
- Aug 15, 2026
- Feed role
- C2
- Host form
- 3 IP / 0 hostnames
Tsundere is a Node.js-based Windows malware family described as a botnet or backdoor platform that executes arbitrary JavaScript received from its command-and-control infrastructure.
Profile source: Mallory opens in a new tabTsundere
Tsundere is a Node.js-based Windows malware family described as a botnet or backdoor platform that executes arbitrary JavaScript received from its command-and-control infrastructure. It is associated in multiple investigations with blockchain-based command-and-control discovery, using Ethereum-hosted data or smart-contract logic to resolve or refresh live server details before establishing WebSocket communications. This design provides resilience against infrastructure disruption and enables operators to rapidly rotate command-and-control endpoints.
Observed Tsundere infections have been delivered through fraudulent MSI installers that deploy Node.js together with legitimate libraries and then launch the malicious JavaScript components. The malware validates resolved command-and-control information, opens a WebSocket channel, and executes attacker-supplied JavaScript on the infected host, giving operators flexible post-compromise control. Reported variants and closely related components have also incorporated persistence logic and EtherHiding-style command-and-control resolution.
Tsundere has been linked by several researchers to activity involving Iranian state-aligned MuddyWater, including a variant referred to as DinDoor, while other reporting notes similarities to Russian-speaking criminal tradecraft and shared infrastructure patterns with other malware. Attribution of original development remains uncertain, but the malware has been observed in operations targeting Windows environments and has appeared alongside other malware-as-a-service or criminal ecosystem tooling. High-confidence reporting supports Windows targeting, JavaScript-based remote execution, persistence in some deployments, and blockchain-assisted command-and-control resilience.
C2 tracking
Derp observations, rolling seven-day window
Reported operators
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
“CastleRAT” refers specifically to the native PE component of the malware; ChainShell and the Deno-based “Tsundere” variants are separate TAG-150 platform components deployed alongside CastleRAT by the same operator.
During the engagement, TRU found on that server a malicious file with functionality to establish persistence and deploy the Tsundere botnet malware, which also integrates the “EtherHiding” C2 resolution logic.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.