Tsundere Botnet

MITRE ATT&CK: S9034 View on attack.mitre.org

Aliases: DinDoor, Tsundere Botnet

First seen
2025-06-01 00:00:00
Malware type
botnet
Family
Malware family
Operating systems
linux, macos, windows
Related IoCs
6 (6 malicious)
Last IoC activity
2026-08-27 12:43:22
Profile updated
2026-07-07 14:28:59

Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications

Context

Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor. A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.

Recent IoC activity

6 malicious indicators in Maltiverse are attributed to Tsundere Botnet (S9034). The 6 most recently updated:

TypeIndicatorUpdatedSources
file sample 1480dabe89af53f798ac93d4606d37ad8a1e6938dc054460ed4d8548f5e18d70 2026-08-27 2
file sample 0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542.msi 2026-08-17 2
file sample 25577967419.zip 2026-07-28 1
file sample 1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1.msi 2026-07-18 2
file sample c23fc7b74370d590223d962727e67907.msi 2026-07-18 2
file sample Installer_v1.21.66.msi 2026-07-18 2

Detection coverage

  • 436 Sigma rules

Malware & tools used

  • Exfiltration to Cloud Storage (attack-pattern)
  • Execution Guardrails (attack-pattern)
  • Web Protocols (attack-pattern)
  • System Location Discovery (attack-pattern)
  • Compromise Software Dependencies and Development Tools (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Dead Drop Resolver (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • JavaScript (attack-pattern)
  • PowerShell (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Msiexec (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Hidden Window (attack-pattern)

Used by threat actors

Reports & references

  • research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
  • Kaspersky — 117979 (report)
  • MITRE ATT&CK — S9034 (report)
  • ctrlaltintel.com — Muddywater (report)
  • socradar.io — Iran Muddywater Dindoor Malware Us Networks (report)

External references