Wisteria Tsunami
Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
Wisteria Tsunami is an India-based private sector offensive actor targeting South Asian governments for intelligence collection.
Wisteria Tsunami, tracked as DEV-0605 and also known as CyberRoot or MintedSoil, is an India-based private sector offensive actor (PSOA). The group primarily targets government entities, diplomatic missions, and political organizations in South Asia for intelligence collection. Key TTPs include targeted phishing for credential harvesting, DLL side-loading, and custom malware for post-exploitation command and control (C2). Defenders should focus on signs of email-borne initial access and unusual DLL loading events, while enforcing MFA for politically exposed personnel.
Microsoft threat actor profile. Origin/Threat: India, Private sector offensive actor.
The group primarily targets government entities, diplomatic missions, and political organizations in South Asia for intelligence collection.
The key tactic is targeted phishing for credential harvesting. Defenders should focus on signs of email-borne initial access and enforce MFA for politically exposed personnel.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.