Denim Tsunami

Aliases: KNOTWEED, DSIRF, DEV-0291

First seen
2022-07-01 00:00:00
Origin
AT
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
nation-state
Profile updated
2026-07-07 12:12:22

Targeted industries: government-and-public-sector financial-services technology-and-telecommunications

Targeted regions: country_code:de country_code:fr country_code:es country_code:at country_code:pa

Context

Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using multiple Windows and Adobe 0-day exploits, including one for CVE-2022-22047, which is a privilege escalation vulnerability. Denim Tsunami developed a custom malware called Subzero, which has capabilities such as keylogging, capturing screenshots, data exfiltration, and running remote shells. They have also been associated with the Austrian spyware distributor DSIRF.

Exploited vulnerabilities

  • CVE-2022-22047 (vulnerability)

Reports & references

  • thezdi.com — Activation Context Cache Poisoning Exploiting Csrss For Privilege Escalation (report)
  • socradar.io — Threats Of Commercialized Malware Knotweed (report)
  • Microsoft — Untangling Knotweed European Private Sector Offensive Actor Using 0 Day Exploits (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)

External references