ATT&CKReferencesSecureListUbiedo_Tsundere_Nov2025

SecureListUbiedo_Tsundere_Nov2025

Ubiedo, L. (2025, November 20). Blockchain and Node.js abused by Tsundere: an emerging botnet. Retrieved April 6, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples15

TechniqueUsed byProcedure example
T1027.010
Command Obfuscation
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has Base64-encoded command execution.

T1036.005
Match Legitimate Resource Name or Location
MalwareTsundere Botnet

Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software.

T1059.001
PowerShell
MalwareTsundere Botnet

Tsundere Botnet has been distributed via a PowerShell script.

T1059.007
JavaScript
MalwareTsundere Botnet

Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component.

T1071.001
Web Protocols
MalwareTsundere Botnet

Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes.

T1082
System Information Discovery
MalwareTsundere Botnet

Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information.

T1102.001
Dead Drop Resolver
MalwareTsundere Botnet

Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes.

T1105
Ingress Tool Transfer
MalwareTsundere Botnet

Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool.

T1140
Deobfuscate/Decode Files or Information
MalwareTsundere Botnet

Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector.

T1195.001
Compromise Software Dependencies and Development Tools
MalwareTsundere Botnet

Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload.

T1218.007
Msiexec
MalwareTsundere Botnet

Tsundere Botnet has been distributed via an MSI installer.

T1480
Execution Guardrails
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region.

T1547.001
Registry Run Keys / Startup Folder
MalwareTsundere Botnet

Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login.

T1564.003
Hidden Window
MalwareTsundere Botnet

Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user.

T1614
System Location Discovery
MalwareTsundere Botnet

Tsundere Botnet has checked the victim machine’s location by obtaining the culture name of the machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.