Tsunami is an open-source, Linux-based DDoS botnet malware family and backdoor derived from Kaiten, also known as Titan or Ziggystartux. It uses IRC for command and control, connecting infected systems to operator-controlled servers and awaiting instructions. Core functionality includes remote shell command execution, file downloads, and distributed denial-of-service attacks. Some variants use encrypted IRC messages.
Tsunami has been deployed against Linux servers, cloud instances, containerized environments, and embedded devices. Observed infection chains exploit exposed or misconfigured services, including Docker daemons and Jenkins dashboards, as well as vulnerabilities in Oracle WebLogic, Apache Log4j, and Atlassian Confluence. Installation commonly involves shell scripts that retrieve and execute architecture-compatible payloads, including 32-bit and 64-bit Linux builds. Tsunami is frequently deployed alongside separate cryptocurrency miners and propagation utilities; cryptocurrency mining is not established as a core Tsunami capability.
Operators using Tsunami include TeamTNT, the 8220 Gang, and Keksec. TeamTNT and the 8220 Gang have used it to maintain remote access during attacks on cloud and container infrastructure. Keksec has heavily modified its open-source code, with variants incorporating Telnet weak-password attacks, vulnerability scanning, and packet sniffing that forwards selected TCP traffic to command-and-control infrastructure. Muhstik is a Tsunami-derived botnet with expanded propagation functionality. Tsunami's use by multiple unrelated operators makes the family alone insufficient for threat-actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During routine sandbox hunting analysis, the Uptycs Threat Research team uncovered evidence of an ongoing live campaign exploiting the Log4j vulnerability, which commenced in January 2024.
CVE-2018-20062 is a ThinkPHP Remote Code Execution Vulnerability.
In the latter instead, it was exploited the well-known vulnerability CVE-2020-14882. It was patched more than one year ago, but the targeted container image was not updated, and so it was still vulnerable. | The Sysdig Research Team has just discovered a new sample of Tsunami malware targeting Jenkins and Weblogic services deployed in Kubernetes clusters.
The vulnerability was added to the National Vulnerability Database (NVD) as CVE-2022-26134. It affects several versions of Confluence servers and data centers, allowing an unauthenticated attacker to execute arbitrary code and exploit vulnerable versions.
We observed two distinct exploitation attempts: one targeting Linux (m.xml) and another one targeting Windows (m1.xml).
The attacker primarily exploited the CVE-2020-14883 vulnerability, occasionally leveraging of CVE-2017-10271.
During the implant phase, Muhstik forces targeted GPON devices to download muhstik.tsunami malicious code.
During the implant phase, Muhstik forces targeted GPON devices to download muhstik.tsunami malicious code.
The Muhstik botnet exploits Drupal vulnerability (CVE-2018-7600), impacting versions 6,7, and 8 of Drupal’s CMS platform.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
The downloaded payload (md5: aec2df8a6cb35aa5b01b0d9f1f879aa1) is an x86_64 ELF executable that was submitted to VirusTotal and detected by many vendors as Tsunami/Kaiten. It mainly functions as a DDoS client, but also has backdoor capabilities, communicating over IRC.
6 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Tsunami - An open-source botnet, aslo known as titan or ziggystartux, used to perform DDoS attacks against targets or to execute commands on the infected machine.
Further analysis shows that this IP and another Necro C2 IP 193.239.147.224 were also used as C2 by other versions of Gafgyt and Tsunami botnet in early February, which apparently share code with Gafgyt_tor.
Keksec actively maintains three main families, Gafgyt, Tsunami and Necro, with new features constantly being added.
Further, it makes a bunch of references to a TSUNAMI payload which STRIKE hasn’t analyzed, and its role is unknown.
During our analysis we were able to identify a more comprehensive sample of the Tsunami-Framework, a Malware relying on the TOR-Network and Pastebin for command and control. Tsunami has a modular structure, incorporates multiple stealers and deploys two cryptominers.
31 distinct techniques documented for this family, organized by ATT&CK tactic.
Based on our research, we have discerned that this botnet perpetually scans the entirety of the internet... every IP address undergoes a scan at least once every hour.
We can see that Keksec launched scans and attacks on targets across the network almost non-stop. Our honeypots see new variants and exploits all the time, with the exception of some occasional breaks. When a new exploit is introduced, the scans increase significantly.
It then adds a Windows-Defender Exclusion for the “Runtime Broker.exe” and creates a Scheduled Task for secondary persistence.
The mass scanning activity observed so far has involved attempts at installing several cryptocurrency miners and the Tsunami backdoor.
In terms of execution and the download command is a bash implementation used to download scripts and binaries from the C2 server.
When Tsunami is executed, it writes its own path in the “/etc/rc.local” file, making it so that it runs even after reboots.
When Tsunami is executed, it writes its own path in the “/etc/rc.local” file, making it so that it runs even after reboots.
It then adds a Windows-Defender Exclusion for the “Runtime Broker.exe” and creates a Scheduled Task for secondary persistence.
in a fileless malware attack, the malware is loaded into memory and then executed. By executing malicious code directly from memory, attackers can evade detection by static scanners
Most of the Gafgyt and Tsunami samples we captured were not packed... String encoding... Necro also cryptographically protects the string by first performing character substitution and then doing zip compression.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
The scanners used by Keksec are mainly telnet and SSH weak password scan and exploit scan.
Packet sniffing is one of the more favoured features of Keksec, and the code can be seen in all three families. The basic function is to capture TCP traffic after filtering out some specified ports and IPs, and to send the remaining data to the C2.
“The core function is still DDoS attacks and scanning”; samples contain scan functions named “ak47Scan” and “ak47telscan.”
Keksec’s malware mainly uses Gafgyt and IRC protocols to send commands.
The IRC protocol is the most widely used protocol in Keksec, and is supported by the Tsunami, Necro and DarkIRC families.
272 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
56 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
IRC-controlled backdoor that allows attackers to execute shell commands, download files, and launch DDoS attacks. The reported campaign compromised Jenkins through dashboard misconfiguration and WebLogic through CVE-2020-14882, using remote command execution to download scripts and architecture-specific Tsunami binaries. An unnamed miner also ran on the compromised systems. The infected host subsequently downloaded sshexec and sshpass, enabling SSH command execution and SCP file transfers against additional hosts. Researchers could not reconstruct the encrypted IRC communications.
A MIPS-based IoT malware family included as one of seven balanced malware-family classes in the proof-of-concept EMBeD benchmark dataset.
A MIPS-based IoT malware family included in the EMBeD proof-of-concept benchmark dataset.
Mentioned as a dropper referenced in inactive remote-code-execution code within the analyzed TuxBot ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.