The Tsundere botnet uses the Ethereum blockchain to infect its targets
Essential information
- Published
- 20/11/2025 22:12
- Modified
- 21/11/2025 09:36
- Tags
- 123 stealer 2025-11-20 aes-256 botnet ethereum javascript koneko msi node.js powershell tsundere tsundere bot websocket
- Related entities
- 21 observables, 1 intrusion sets (apt), 20 techniques (mitre), 2 malware
Description
The Tsundere botnet, discovered in mid-2025, is an active threat targeting Windows users. It utilizes the Ethereum blockchain to retrieve C2 addresses and employs Node.js for its operations. The botnet spreads through MSI installers and PowerShell scripts, often disguised as popular games. It uses AES-256 CBC encryption for communication and can execute dynamic JavaScript code received from the C2 server. The botnet features a marketplace and control panel, allowing users to create and sell customized bots. Attributed to a Russian-speaking actor known as 'koneko', Tsundere is linked to the 123 Stealer and represents an evolution of previous attacks. Its use of smart contracts for C2 infrastructure enhances its resilience, making it a significant emerging threat.