Tsundere Botnet Malware — Analysis, Campaigns & Threat Activity

Threat entity extracted from intelligence sources

Frequency
4
occurrences
First Seen
November 20, 2025
Last Seen
August 14, 2026

Related Threat Clusters

  • Armored Likho Expands Cyber-Espionage with New Rust Toolkit

    In May 2026, the Armored Likho group, also known as Eagle Werewolf, launched a cyber-espionage campaign targeting private individuals and organizations in Russia, including corporations, government bodies, and…

    2 articles · Updated August 13, 2026
  • DinDoor Backdoor Uses Deno Runtime and MSI Installers to Evade Detection

    A newly identified backdoor, DinDoor, exploits the Deno JavaScript runtime and MSI installer files to execute malicious code while avoiding detection. This malware is associated with the Tsundere Botnet and leverages…

    2 articles · Updated April 22, 2026
  • Emergence of Tsundere Botnet Exploiting Node.js and Cryptocurrency Packages

    The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, targets Windows, Linux, and macOS users by leveraging legitimate Node.js packages and blockchain technology. Initially observed in October 2024, it…

    1 article · Updated November 20, 2025
  • Emergence of Tsundere Botnet Targeting Windows Users

    The Tsundere botnet, discovered by Kaspersky in July 2025, targets Windows systems through a fake MSI installer masquerading as game setup files. It has been detected in multiple countries including Mexico, Chile,…

    2 articles · Updated November 21, 2025
  • Malicious npm Packages Use Adspect Cloaking in Crypto Scam

    A malware campaign has been identified that utilizes malicious npm packages to create fake websites designed to identify and exploit potential victims. The threat actor, known as 'dino_reborn', published these packages…

    13 articles · Updated November 18, 2025
  • Tsundere Botnet Exploits Node.js and Blockchain for Multi-OS Attacks

    The Tsundere botnet, identified by Kaspersky GReAT in mid-2025, utilizes legitimate Node.js packages and blockchain technology to distribute malware targeting Windows, Linux, and macOS users. The threat is linked to…

    2 articles · Updated November 20, 2025

Recent Intelligence Reports

  • Dead Drop Resolver — attack.mitre.org · August 14, 2026
  • New DinDoor Backdoor Abuses Deno Runtime and MSI Installers to Evade Detection — Cybersecuritynews · April 22, 2026
  • Cute but deadly: Kaspersky reveals the Tsundere botnet that plays hot-and — Kaspersky · November 20, 2025
  • Tsundere Botnet Abusing Popular Node.js and Cryptocurrency Packages to Attack Windows, Linux, and macOS Users — Cybersecuritynews · November 20, 2025

CVSS v3.1 Breakdown