ThreatCluster

Emergence of Tsundere Botnet Exploiting Node.js and Cryptocurrency Packages

First seen 23 Nov 2025, 03:35 UTC Cybersecuritynews 0% similarity 29

Article Content

Browse articles
ThreatCluster

The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, targets Windows, Linux, and macOS users by leveraging legitimate Node.js packages and blockchain technology. Initially observed in October 2024, it utilizes a malicious MSI installer and exploits the Ethereum blockchain for command-and-control operations.

ThreatCluster AI How this analysis works

Community

Browse all →

Tracked Entities in This Story