Related Threat Clusters
-
TA584 Expands Operations with Tsundere Bot via ClickFix Social Engineering
The cybercriminal group TA584 has intensified its operations by deploying Tsundere Bot malware through ClickFix social engineering tactics. This initial access broker has significantly increased its campaign volume,…
5 articles · Updated January 29, 2026 -
Emergence of Tsundere Botnet Targeting Windows Users
The Tsundere botnet, discovered by Kaspersky in July 2025, targets Windows systems through a fake MSI installer masquerading as game setup files. It has been detected in multiple countries including Mexico, Chile,…
2 articles · Updated November 21, 2025 -
Malicious npm Packages Use Adspect Cloaking in Crypto Scam
A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…
13 articles · Updated November 18, 2025 -
Tsundere Botnet Exploits Node.js and Blockchain for Multi-OS Attacks
The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, utilizes legitimate Node.js packages and blockchain technology to distribute malware targeting Windows, Linux, and macOS users. The threat is linked to…
2 articles · Updated November 20, 2025
Recent Intelligence Reports
- Initial access hackers switch to Tsundere Bot for ransomware attacks — Bleepingcomputer · January 28, 2026
- Nascent Tsundere botnet examined — Scworld · November 21, 2025
- Cute but deadly: Kaspersky reveals the Tsundere botnet that plays hot-and — Kaspersky · November 20, 2025
- Blockchain and Node.js abused by Tsundere: an emerging botnet — Securelist · November 20, 2025