123 Stealer Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 20, 2025
Last Seen
January 28, 2026

Related Threat Clusters

  • TA584 Expands Operations with Tsundere Bot via ClickFix Social Engineering

    The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…

    5 articles · Updated January 29, 2026
  • Emergence of Tsundere Botnet Targeting Windows Users

    The Tsundere botnet, discovered by Kaspersky in July 2025, targets Windows systems through a fake MSI installer masquerading as game setup files. It has been detected in multiple countries including Mexico, Chile,…

    2 articles · Updated November 21, 2025
  • Malicious npm Packages Use Adspect Cloaking in Crypto Scam

    A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…

    13 articles · Updated November 18, 2025
  • Tsundere Botnet Exploits Node.js and Blockchain for Multi-OS Attacks

    The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, utilizes legitimate Node.js packages and blockchain technology to distribute malware targeting Windows, Linux, and macOS users. The threat is linked to…

    2 articles · Updated November 20, 2025

Recent Intelligence Reports

  • Initial access hackers switch to Tsundere Bot for ransomware attacks — Bleepingcomputer · January 28, 2026
  • Nascent Tsundere botnet examined — Scworld · November 21, 2025
  • Cute but deadly: Kaspersky reveals the Tsundere botnet that plays hot-and — Kaspersky · November 20, 2025
  • Blockchain and Node.js abused by Tsundere: an emerging botnet — Securelist · November 20, 2025

CVSS v3.1 Breakdown