Skip to content

Incidents attributed to:

Denim Tsunami

Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers.

Denim Tsunami is a threat actor group that has been involved in targeted attacks against European and Central American customers. They have been observed using multiple Windows and Adobe 0-day exploits, including one for CVE-2022-22047, which is a privilege escalation vulnerability. Denim Tsunami developed a custom malware called Subzero, which has capabilities such as keylogging, capturing screenshots, data exfiltration, and running remote shells. They have also been associated with the Austrian spyware distributor DSIRF.

Also known as

KNOTWEED, DSIRF.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).