1
Groups Using This
3
Platforms
178
Prevalence Rank
0
Known Aliases
Description

Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor. A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.

View MITRE record ↗

Platforms
LinuxmacOSWindows
Groups Deploying Tsundere Botnet (1)
↑