Threat Intelligence

Nascent Tsundere botnet examined

botnet computer virus red background

Windows systems have been increasingly targeted by the newly emergent Tsundere botnet, which facilitates arbitrary JavaScript code execution, The Hacker News reports.

Tsundere has been executed through a phony MSI installer that delivers Node.js and three legitimate libraries, one of which ensures its operations, according to a Kaspersky analysis. After leveraging the Ethereum blockchain to retrieve WebSocket command-and-control server details to facilitate infrastructure rotation, Tsundere ensures the validity of the obtained C2 address before creating a WebSocket connection and receiving JavaScript code.

"The ability to evaluate code makes the Tsundere bot relatively simple, but it also provides flexibility and dynamism, allowing the botnet administrators to adapt it to a wide range of actions," said Kaspersky.

While details regarding the perpetrator of Tsundere remain uncertain, such a botnet is believed to have been developed by a Russian-speaking threat actor. Aside from being similar to a Russian npm campaign discovered last year, Tsundere was also found to have the same server as the 123 Stealer's C2 panel.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds