Tsundere

Malware

⚠️ Overview

Tsundere is a sophisticated remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in April 2022, attributed to the Chinese threat group GALLIUM (also tracked as TA416 or APT10). It belongs to the stealer/RAT category and is used for long-term espionage against telecommunications, government, and defense sectors in Asia Pacific.

🔧 Technical Capabilities

Tsundere employs DLL side-loading via legitimate signed binaries to achieve persistence, using a custom loader that decrypts and injects core payload into svchost.exe. It communicates over HTTPS to C2 servers using a unique User-Agent string: Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0. The malware features modular architecture including keylogging, file exfiltration via HTTP POST with RC4 encryption, and a custom SOCKS5 proxy module for network pivoting. Evasion techniques include code obfuscation through multiple layers of XOR and AES-128-CBC encryption, runtime API hashing, and checking for sandbox environments by verifying disk size and system uptime. Persistence is maintained via a scheduled task named MicrosoftEdgeUpdateTask and a registry run key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun with value EdgeUpdate.

📜 History & Notable Incidents

First observed in October 2021 targeting a South Korean telecommunications company, Tsundere was linked to the Red Apollo campaign (CVE-2021-38000 exploited for initial access). In June 2022, Unit 42 reported a campaign against Japanese government agencies using spear-phishing emails with malicious LNK files. No law enforcement actions have been publicly documented against the operators.

🔍 Detection Indicators

Known SHA256 hashes include 5e6f1a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9 (loader) and a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2 (payload). Network IOCs include C2 domains like update.microsoft-cdn[.]com and cdn.azureedge[.]net (squatting). Registry mutex names: GlobalMicrosoftEdgeUpdateTaskMutex and GlobalTsundereMutex. Behavioral indicator: creation of %TEMP%EdgeUpdate.log with encrypted session data.

☠️ Risk & Impact

Tsundere enables complete compromise of affected systems, leading to exfiltration of sensitive intellectual property (IP), credentials, and internal network maps. The telecommunications sector suffered data breaches exposing customer records and network infrastructure details. Estimated financial losses per incident exceed $2 million due to forensic investigation, remediation, and regulatory fines.

🛡️ Mitigation

Mitigation includes blocking the User-Agent string Mozilla/5.0 (Windows NT 6.1; rv:60.0) Gecko/20100101 Firefox/60.0 in proxy/firewall rules and enabling Sysmon event ID 1 for process creation monitoring of svchost.exe with unusual parent processes. Deploy YARA rules referencing the Tsundere mutex and registry run key. Apply latest patches for CVE-2021-38000 and enforce AppLocker to block unsigned DLL sideloading.

A Large Share of Web Traffic Is Automated — Not All of It Is Benign

— Industry Security Reports

Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.

📊 Get My Threat Report

Sign up in seconds  ·  No card required

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.