Tsundere Botnet
MITRE ATT&CK: S9034 View on attack.mitre.org
Aliases: DinDoor, Tsundere Botnet
- First seen
- 2025-06-01 00:00:00
- Malware type
- botnet
- Family
- Malware family
- Operating systems
- linux, macos, windows
- Related IoCs
- 6 (6 malicious)
- Last IoC activity
- 2026-08-27 12:43:22
- Profile updated
- 2026-07-07 14:28:59
Targeted industries: government-and-public-sector energy-and-utilities technology-and-telecommunications
Context
Tsundere Botnet is a botnet first reported in mid-2025 that is delivered via MSI installer or a PowerShell script. It leverages Node.js and JavaScript for payload delivery and execution, and uses smart contracts on the blockchain to host command and control (C2) addresses. Tsundere Botnet is attributed to a likely Russian-speaking threat actor. A variant named DinDoor has been linked to MuddyWater operations and uses the Deno runtime for execution rather than Node.js.
Recent IoC activity
6 malicious indicators in Maltiverse are attributed to Tsundere Botnet (S9034). The 6 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 1480dabe89af53f798ac93d4606d37ad8a1e6938dc054460ed4d8548f5e18d70 | 2026-08-27 | 2 |
| file sample | 0f9cf1cf8d641562053ce533aaa413754db88e60404cab6bbaa11f2b2491d542.msi | 2026-08-17 | 2 |
| file sample | 25577967419.zip | 2026-07-28 | 1 |
| file sample | 1d984d4b2b508b56a77c9a567fb7a50c858e672d56e8cf7677a1fca5c98c95d1.msi | 2026-07-18 | 2 |
| file sample | c23fc7b74370d590223d962727e67907.msi | 2026-07-18 | 2 |
| file sample | Installer_v1.21.66.msi | 2026-07-18 | 2 |
Detection coverage
- 436 Sigma rules
Malware & tools used
- Exfiltration to Cloud Storage (attack-pattern)
- Execution Guardrails (attack-pattern)
- Web Protocols (attack-pattern)
- System Location Discovery (attack-pattern)
- Compromise Software Dependencies and Development Tools (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Dead Drop Resolver (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- JavaScript (attack-pattern)
- PowerShell (attack-pattern)
- Command Obfuscation (attack-pattern)
- System Information Discovery (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Msiexec (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Hidden Window (attack-pattern)
Used by threat actors
- MuddyWater (threat-actor)
Reports & references
- research.checkpoint.com — Iranian Mois Actors The Cyber Crime Connection (report)
- Kaspersky — 117979 (report)
- MITRE ATT&CK — S9034 (report)
- ctrlaltintel.com — Muddywater (report)
- socradar.io — Iran Muddywater Dindoor Malware Us Networks (report)