Initial access hackers switch to Tsundere Bot for ransomware attacks
In order to obtain network access that potentially result in ransomware attacks, a prolific initial access broker known as TA584 has been seen leveraging the Tsundere Bot in conjunction with the XWorm remote access trojan.
According to Proofpoint experts who have been monitoring TA584's activities since 2020, the threat actor has recently greatly expanded its operations, launching a continuous assault chain that compromises static detection. Kaspersky initially reported Tsundere Bot last year, attributing it to a Russian-speaking operator with connections to the 123 Stealer virus.
Proofpoint claims that the virus can be used for information gathering, data exfiltration, lateral movement, and the installation of additional payloads, even if its objectives and mode of infection were s...

