SendGrid A.I CyberSecurity Scoring
SendGrid
Company Information
Website:https://http://www.sendgrid.com/
Employees number:41
Number of followers:20,135
NAICS:
Industry Type:Information Technology & Services
Homepage:sendgrid.com
SendGrid Risk Score (AI oriented)
Between 700 and 749
SendGridInformation Technology & Services
Updated:
10/03/2026
10/03/2026
737/1000
Moderate
Ba
SendGrid Global Score (TPRM)
xxxx
SendGridInformation Technology & Services
Score locked

SendGridModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-19 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
738
MAY 2026
738
APRIL 2026
737
MARCH 2026
737
FEBRUARY 2026
736
JANUARY 2026
736
DECEMBER 2025
735
NOVEMBER 2025
735
OCTOBER 2025
753
Cyber Attack
01 Oct 2025 • SendGrid
SendGrid: Initial access hackers switch to Tsundere Bot for ransomware attacks
TA584 Initial Access Broker Expands Operations with Tsundere Bot and XWorm in Ransomware-Linked Campaigns
734
CRITICAL-19
SEN1769647301
TA584 Initial Access Broker Expands Operations with Tsundere Bot and XWorm in Ransomware-Linked Campaigns
A prolific initial access broker (IAB) tracked as TA584 has escalated its activity, deploying the Tsundere Bot malware alongside the XWorm remote access trojan (RAT) to compromise networks likely as a precursor to ransomware attacks. Researchers at Proofpoint, who have monitored the group since 2020, report a threefold increase in TA584’s campaign volume in late 2025, expanding its targeting beyond traditional regions (North America, UK/Ireland) to include Germany, other European countries, and Australia.
### Attack Chain & Tactics
TA584’s latest campaigns begin with phishing emails sent via compromised, aged accounts using SendGrid and Amazon SES. Each target receives a unique URL, with geofencing, IP filtering, and redirect chains (often leveraging Keitaro TDS) to evade detection. Victims who bypass these filters encounter a CAPTCHA page, followed by a ClickFix prompt instructing them to execute a PowerShell command a tactic designed to bypass static defenses.
The command fetches an obfuscated script that loads XWorm or Tsundere Bot into memory, while the browser redirects to a benign site to mask the infection. TA584 has historically deployed a range of payloads, including Ursnif, LDR4, WarmCookie, Xeno RAT, Cobalt Strike, and DCRAT (still observed in 2025).
### Tsundere Bot: A Malware-as-a-Service Threat
Originally documented by Kaspersky in 2024 and linked to a Russian-speaking operator (with ties to 123 Stealer), Tsundere Bot functions as both a backdoor and loader. Key features include:
- Node.js dependency: The malware installs Node.js on victim systems via its command-and-control (C2) panel.
- Blockchain-based C2 retrieval: Uses a variant of EtherHiding to fetch C2 addresses from the Ethereum blockchain, with a hardcoded fallback.
- WebSocket communication: Evades traditional network monitoring.
- Geofencing: Aborts execution if the system locale matches CIS (Commonwealth of Independent States) languages, suggesting Russian origin.
- Data exfiltration & lateral movement: Collects system information, executes arbitrary JavaScript, and can turn infected hosts into SOCKS proxies.
- Bot marketplace: Operators can buy and sell access to compromised machines.
### Broader Implications
Proofpoint assesses with high confidence that Tsundere Bot infections could lead to ransomware deployment, given TA584’s history of facilitating such attacks. The group’s expanded targeting and experimentation with payloads suggest a growing threat, with researchers anticipating further diversification in victims and attack methods.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for SendGrid ??
What was SendGrid's A.I Rankiteo Cyber Score in May 2026 ??
What was SendGrid's A.I Rankiteo Cyber Score in April 2026 ??
What was SendGrid's A.I Rankiteo Cyber Score in March 2026 ??
What was SendGrid's A.I Rankiteo Cyber Score in February 2026 ??
What was SendGrid's A.I Rankiteo Cyber Score in January 2026 ??
What was SendGrid's A.I Rankiteo Cyber Score in December 2025 ??
What was SendGrid's A.I Rankiteo Cyber Score in November 2025 ??
What was SendGrid's A.I Rankiteo Cyber Score in October 2025 ??
What was SendGrid's A.I Rankiteo Cyber Score in September 2025 ??
What was SendGrid's A.I Rankiteo Cyber Score in August 2025 ??
What was SendGrid's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on SendGrid's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with SendGrid ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view SendGrid's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?