Also known as: DEV-0605, CyberRoot, MintedSoil, tracked as, SamSam
Wisteria Tsunami, also known by aliases DEV‑0605 and MintedSoil (sometimes referenced as SamSam in certain feeds), is identified as a private‑sector threat actor originating from India. The organization leverages a diverse set of delivery mechanisms and backdoor families, notably Ghost RAT—a long‑standing remote access trojan—and SUNBURST, a sophisticated backdoor used for stealthy deployment and persistence. Early indicators suggest the group’s operational maturity includes capabilities in credential harvesting, lateral movement through legitimate services, and exfiltration via encrypted tunnels. By embedding its malware into legitimate administrative tools and using open‑source components such as Emissary and InvisibleFerret, Wisteria Tsunami obscures its footprint while maintaining a broad reach across multiple industry sectors. The actor’s persistence strategy reflects a blend of well‑known and newer threat tools (e.g., BANSHEE, OceanLotus, Dark), indicative of an evolving playbook that incorporates both legacy RATs and the latest ransomware and supply‑chain compromise techniques. Despite limited public attribution of specific campaigns, intelligence points to repeated engagement with financial gains through theft, extortion, or opportunistic exploitation. Overall, Wisteria Tsunami demonstrates a clear intent to monetize cyber operations at scale, targeting global organizations with diverse value chains while relying on a toolbox that blends persistent remote access, stealthy backdoors, and data‑exfiltration tactics.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Wisteria Tsunami is a private‑sector offensive actor based in India that primarily seeks financial gain by deploying remote access trojans and backdoor malware such as Ghost RAT and SUNBURST. The group targets a broad range of sectors—including finance, government, defense, telecommunications, media, education, and critical infrastructure—while operating in numerous countries including the US, UK, Iran, Afghanistan, and others. Its adversarial capabilities enable persistent remote control, lateral movement, and data exfiltration across targeted networks.
Goals & Targeting
The strategic objective of Wisteria Tsunami is primarily monetary gain. The group deliberately chooses high‑profile targets across government, defense, telecoms, media, education, energy, and manufacturing to maximize the commercial value of stolen credentials, intellectual property, or to execute ransomware campaigns. By focusing on sectors with complex supply chains and often weaker security posture, they exploit lateral movement techniques to pivot laterally within enterprise environments, thereby expanding their reach and value extraction potential.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Operating with a global footprint, Wisteria Tsunami consistently engages in opportunistic campaigns that span multiple industries. The group’s tempo appears episodic but focused: large‑scale data breaches followed by targeted ransomware or credential exfiltration attacks. Victim selection leans toward organizations with significant financial transactions or those that manage critical infrastructure, allowing the actor to maximize leverage for extortion or monetary theft. Past evidence cites links to the Tsunami weather family of threat actors and mentions of supply‑chain involvement through backdoor families such as SUNBURST. While a definitive catalog of campaigns remains incomplete due to limited public disclosures, consistent use of Ghost RAT and SUNBURST suggests a recurring deployment pattern across several incidents.
IOC Patterns
Recommended Actions
No campaigns linked yet.
No observed data linked yet.
5
Techniques
46
Tools
0
Campaigns
5
IOCs
0
Observed Data
1
Tactics