Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Wisteria Tsunami

Also known as: DEV-0605, CyberRoot, MintedSoil, tracked as, SamSam

Description

Wisteria Tsunami, also known by aliases DEV‑0605 and MintedSoil (sometimes referenced as SamSam in certain feeds), is identified as a private‑sector threat actor originating from India. The organization leverages a diverse set of delivery mechanisms and backdoor families, notably Ghost RAT—a long‑standing remote access trojan—and SUNBURST, a sophisticated backdoor used for stealthy deployment and persistence. Early indicators suggest the group’s operational maturity includes capabilities in credential harvesting, lateral movement through legitimate services, and exfiltration via encrypted tunnels. By embedding its malware into legitimate administrative tools and using open‑source components such as Emissary and InvisibleFerret, Wisteria Tsunami obscures its footprint while maintaining a broad reach across multiple industry sectors. The actor’s persistence strategy reflects a blend of well‑known and newer threat tools (e.g., BANSHEE, OceanLotus, Dark), indicative of an evolving playbook that incorporates both legacy RATs and the latest ransomware and supply‑chain compromise techniques. Despite limited public attribution of specific campaigns, intelligence points to repeated engagement with financial gains through theft, extortion, or opportunistic exploitation. Overall, Wisteria Tsunami demonstrates a clear intent to monetize cyber operations at scale, targeting global organizations with diverse value chains while relying on a toolbox that blends persistent remote access, stealthy backdoors, and data‑exfiltration tactics.

Goals & Targeting

Targeted Sectors

Financial services
Government
Defense
Telecommunications
Media
Non profit
Education
Energy
Think tank
Pharmaceutical
Manufacturing
Chemical
Information technology
Gaming
Maritime
Legal services
Mining
Utilities

Targeted Countries / Regions

IN
IR
CN
KP
RU
IL
US
GB
UA
VN
TR
LB
KR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 15 hours ago

Executive Summary

Wisteria Tsunami is a private‑sector offensive actor based in India that primarily seeks financial gain by deploying remote access trojans and backdoor malware such as Ghost RAT and SUNBURST. The group targets a broad range of sectors—including finance, government, defense, telecommunications, media, education, and critical infrastructure—while operating in numerous countries including the US, UK, Iran, Afghanistan, and others. Its adversarial capabilities enable persistent remote control, lateral movement, and data exfiltration across targeted networks.

Goals & Targeting

The strategic objective of Wisteria Tsunami is primarily monetary gain. The group deliberately chooses high‑profile targets across government, defense, telecoms, media, education, energy, and manufacturing to maximize the commercial value of stolen credentials, intellectual property, or to execute ransomware campaigns. By focusing on sectors with complex supply chains and often weaker security posture, they exploit lateral movement techniques to pivot laterally within enterprise environments, thereby expanding their reach and value extraction potential.

Enhanced Description

Key Capabilities

  • Remote Access Trojans
  • Backdoor Deployment

MITRE ATT&CK Tactics

Execution
Persistence
Privilege Escalation
Command & Control

ATT&CK Techniques

T1059 - Command and Scripting Interpreter
T1078 - Valid Accounts
T1086 - PowerShell
T1105 - Ingress Tool Transfer
T1134 - Exfiltration Over Alternative Protocols

Software / Tooling

Ghost RAT
SUNBURST
Emissary
InvisibleFerret
Crimson
BeaverTail
Wingbird
Mango
Agent Tesla
Covenant
Mythic
Sofacy
Sednit
Turla
Winnti
Cobalt
Matrix
Dark
PINEFLOWER
Conti
Luna
Pink
Tsunami
BANSHEE
OceanLotus
WAVESHAPER
PXA Stealer
Athena
BLINDINGCAN
Global
Jackal
BirdCall
Kimsuky
Kraken
Lynx
Void
GitHub
SolarWinds
Labyrinth Chollima
Moonstone Sleet
Citrine Sleet
BARIUM
Hafnium
Smoke Sandstorm
Wicked
Imperial Kitten

Campaigns & Victims

Operating with a global footprint, Wisteria Tsunami consistently engages in opportunistic campaigns that span multiple industries. The group’s tempo appears episodic but focused: large‑scale data breaches followed by targeted ransomware or credential exfiltration attacks. Victim selection leans toward organizations with significant financial transactions or those that manage critical infrastructure, allowing the actor to maximize leverage for extortion or monetary theft. Past evidence cites links to the Tsunami weather family of threat actors and mentions of supply‑chain involvement through backdoor families such as SUNBURST. While a definitive catalog of campaigns remains incomplete due to limited public disclosures, consistent use of Ghost RAT and SUNBURST suggests a recurring deployment pattern across several incidents.

IOC Patterns

  • domain

Recommended Actions

  • Deploy network segmentation to limit lateral movement opportunities; enforce strict perimeter controls for remote access services.
  • Implement and monitor multi‑factor authentication across all privileged accounts to reduce validity of stolen credentials.
  • Maintain up‑to‑date host detection rules for Ghost RAT, SUNBURST, and related backdoor binaries; conduct regular endpoint triage and removal processes.
  • Block known malicious domains (e.g., those identified in threat feeds) using perimeter firewalls or DNS filtering solutions.
  • Conduct ongoing adversary emulation exercises that simulate RAT persistence and exfiltration tactics to assess detection capability.
  • Keep security teams informed of emerging domain indicators such as TEMP.Zagros, TEMP.Periscope, cisa.gov, and 360.net via real‑time threat intelligence streams.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. learn.microsoft.com — Cited by web research for: Global
  2. misp-galaxy.org — Cited by web research for: Matrix
  3. github.com — Cited by web research for: GitHub

Intel Summary

5

Techniques

46

Tools

0

Campaigns

5

IOCs

0

Observed Data

1

Tactics

Tags

APT
espionage
private-sector threat actor
India-origin

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.