Malware.View on attack.mitre.org
Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor.
A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.
| Technique | Procedure example |
|---|---|
| T1027.010 Command Obfuscation |
Tsundere Botnet’s MSI installer has Base64-encoded command execution. |
| T1027.013 Encrypted/Encoded File |
Tsundere Botnet’s loader contained AES-CBC/PKCS7 encrypted blobs, which were descrypted and written to disk. |
| T1036.005 Match Legitimate Resource Name or Location |
Tsundere Botnet has disguised its MSI installer as a fake installer for popular games and software. |
| T1059.001 PowerShell |
Tsundere Botnet has been distributed via a PowerShell script. |
| T1059.007 JavaScript |
Tsundere Botnet has the ability to run JavaScript code from the C2 server. Additionally, Tsundere Botnet has used Node.js to execute JavaScript code for the loader component. |
| T1071.001 Web Protocols |
Tsundere Botnet has obtained the WebSocket C2 address by making remote procedure call (RPC) APIs to Ethereum blockchain nodes. |
| T1082 System Information Discovery |
Tsundere Botnet has collected the machine’s MAC address, total memory, GPU information and other system information. |
| T1102.001 Dead Drop Resolver |
Tsundere Botnet has obtained the C2 address from Ethereum blockchain nodes. |
| T1105 Ingress Tool Transfer |
Tsundere Botnet’s loader component has downloaded the zip file node-v18.17.0-win-x64.zip from the official Node.js website, as well as pm2, a Node.js process management tool. |
| T1140 Deobfuscate/Decode Files or Information |
Tsundere Botnet’s loader has decrypted obfuscated JavaScript files using the AES-256 CBC algorithm, a build-specific key, and initialization vector. |
| T1195.001 Compromise Software Dependencies and Development Tools |
Tsundere Botnet has used the Node Package Manager (npm) to download malicious packages and to deliver the payload. |
| T1218.007 Msiexec |
Tsundere Botnet has been distributed via an MSI installer. |
| T1480 Execution Guardrails |
Tsundere Botnet has checked the victim machine’s location to avoid infecting in the Commonwealth of Independent States (CIS) region. |
| T1547.001 Registry Run Keys / Startup Folder |
Tsundere Botnet has created a value in the `HKCU:\Software\Microsoft\Windows\CurrentVersion\Run` Registry key, ensuring that it is run at login. |
| T1564.003 Hidden Window |
Tsundere Botnet’s MSI installer has used `-WindowStyle Hidden` to hide Tsundere Botnet’s execution from the user. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.