Initial access hackers switch to Tsundere Bot for ransomware attacks
嗯,用户让我用中文总结一篇文章,控制在100字以内,而且不需要特定的开头。我得先仔细读一下这篇文章。 文章主要讲的是TA584这个初始访问代理,他们使用Tsundere Bot和XWorm远程访问木马来获取网络访问权限,可能引发勒索软件攻击。Proofpoint的研究人员从2020年开始追踪TA584的活动,最近他们的活动显著增加,攻击链更复杂,绕过了静态检测。 Tsundere Bot是Kaspersky去年记录的,与俄罗斯语系的操作者有关联,可能用于信息收集、数据外泄、横向移动和安装额外的有效载荷。TA584在2025年底的活动量比第一季度增加了三倍,并扩展到了欧洲和澳大利亚。 攻击链开始于通过SendGrid和亚马逊SES发送的钓鱼邮件,包含独特的URL和地理围栏过滤。通过CAPTCHA和ClickFix页面后,受害者运行PowerShell命令,下载并执行XWorm或Tsundere Bot。 Tsundere Bot作为服务使用Node.js,并从以太坊区块链获取C2地址。它还检查系统语言,如果是CIS国家的语言就会终止执行。此外,它还收集系统信息、执行JS代码,并支持 SOCKS代理功能。 总的来说,这篇文章详细描述了TA584如何利用复杂的攻击链和多种恶意软件来扩大影响力,并可能引发勒索软件攻击。 </think> 文章描述了TA584团伙利用Tsundere Bot和XWorm木马进行网络入侵活动,并可能引发勒索软件攻击。研究人员发现TA584近期大幅扩大了攻击范围,并采用了复杂的攻击链以规避检测。Tsundere Bot具备信息收集、数据外泄等功能,并能通过区块链技术隐藏C2地址。 2026-1-28 23:30:17 Author: www.bleepingcomputer.com(查看原文) 阅读量:0 收藏

Initial access hackers switch to Tsundere Bot for ransomware attacks

A prolific initial access broker tracked as TA584 has been observed using the Tsundere Bot alongside XWorm remote access trojan to gain network access that could lead to ransomware attacks.

Proofpoint researchers have been tracking TA584's activity since 2020 and say that the threat actor has significantly increased its operations recently, introducing a continuous attack chain that undermines static detection.

Tsundere Bot was first documented by Kaspersky last year and attributed to a Russian-speaking operator with links to the 123 Stealer malware.

Wiz

Although the goals and infection method remained murky at the time, Proofpoint says that "the malware can be used for information gathering, data exfiltration, lateral movement, and to install additional payloads."

“Given that Proofpoint has observed this malware used by TA584, researchers assess with high confidence Tsundere Bot malware infections could lead to ransomware,” the researchers note.

TA584 activity in late 2025 tripled in volume compared to Q1 of the same year and expanded beyond the standard targeting scope of North America and the UK/Ireland to include Germany, various European countries, and Australia.

Number of TA584 campaigns
Number of TA584 campaigns
Source: Proofpoint

The currently prevalent attack chain begins with emails sent from hundreds of compromised, aged accounts, delivered via SendGrid and Amazon Simple Email Service (SES).

The emails include unique URLs for each target, geofencing and IP filtering, and a mechanism of redirect chains often involving third-party traffic direction systems (TDS) like Keitaro.

Those who pass the filters will land on a CAPTCHA page, followed by a ClickFix page instructing the target to run a PowerShell command on their system.

CAPTCHA (left) and ClickFix (right) pages
CAPTCHA (left) and ClickFix (right) pages
Source: Proofpoint

The command fetches and executes an obfuscated script, loads either XWorm or Tsundere Bot into memory, and redirects the browser to a benign site for deception.

The PowerShell script
The PowerShell script
Source: Proofpoint

Proofpoint says TA584 has used a large number of payloads over the years, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT, which was still seen in one case in 2025.

Tsundere Bot is a malware-as-a-service platform with backdoor and loader capabilities. It requires Node.js to operate, which the malware adds to the victim system using installers generated from its command-and-control panel.

The malware retrieves its command-and-control (C2) address from the Ethereum blockchain using a variant of the EtherHiding technique, with a hardcoded fallback address also included in the installer.

It communicates with its C2 servers over WebSockets and includes logic to check the system locale, aborting execution if the system is using Commonwealth of Independent States (CIS) country languages (primarily Russian).

Tsundere Bot collects system information to profile infected machines, can execute arbitrary JavaScript code received from the C2, and supports using infected hosts as SOCKS proxies. The malware platform also features a built-in market where bots can be sold and purchased.

The researchers expect TA584 to attempt a broader range of targets and believe that the threat actor will keep experimenting with various payloads.

Wiz

The 2026 CISO Budget Benchmark

It's budget season! Over 300 CISOs and security leaders have shared how they're planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.


文章来源: https://www.bleepingcomputer.com/news/security/initial-access-hackers-switch-to-tsundere-bot-for-ransomware-attacks/
如有侵权请联系:admin#unsafe.sh