securityonline.info 11/24/2025, 1:35:36 AM · via preferred

Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace

Tsundere Botnet Uncovered: Node.js Malware Uses Ethereum Smart Contract for Unkillable C2 and Runs Cybercrime Marketplace

KASPERSKY’S Global Research & Analysis Team (GReAT) has identified a fast-growing botnet called Tsundere that blends Node[.]js implants, blockchain-based C2 retrieval, fake game installers, and a cybercrime marketplace. The group reportedly first appeared in mid-2025 and is linked to a Russian-speaking threat actor, with prior operations involving 287 malicious Node[.]js packages masquerading as Puppeteer, Bignum[.]js, and crypto libraries documented in October 2024.

According to Kaspersky, Tsundere is spread using a mix of Remote Monitoring and Management abuse and fraudulent game installers targeting the piracy community around first-person shooters. The threat actor distributes two formats—an MSI Installer (Fake Game Setup) and a PowerShell infector—both of which reconstruct a full Node[.]js environment on the victim machine and install ws, ethers and pm2.

The bot retrieves its C2 address by querying a smart contract on Ethereum (Contract: 0xa1b40044EBc2794f207D45143Bd82a1B86156c6b; Wallet: 0x73625B6cdFECC81A4899D221C732E1f73e504a32), with a 24-byte string parameter1 containing the WebSocket C2 address such as ws://185.28.119[.]179:1234. Tsundere features an openly accessible control panel, Tsundere Netto v2.4.4, with open registration and a marketplace for bots and add-ons, and at any given time 90–115 bots are actively connected.

View full article

Article by CyberSIXT