Threats Tagged 'tor'
View all threats tagged with 'tor'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'tor'
Click on any threat for detailed analysis and mitigation recommendations
A new ClickFix campaign targets Windows users with a NodeJS-based infostealer delivered via malicious MSI installers. This highly adaptable remote access Trojan minimizes forensic footprints through dynamic capability loading, with core stealing modules and communication protocols delivered in-memory only after C2 connection. The malware routes gRPC streaming traffic over Tor network for persistent, masked bidirectional channels. An operational security failure exposed server-side admin panel protocol definitions, revealing a malware-as-a-service backend designed to manage multiple operators and automate cryptocurrency asset tracking. The modular architecture delivers malicious logic dynamically as strings executed in-memory, bypassing static signature detection while supporting full RAT functionality including shell command execution and wallet tracking. Join the discussion | AlienVault OTX General | 08/19/2026, 11:25:09 UTC Added: 08/19/2026, 15:52:33 UTC |
This analysis examines Infostealer malware trends during December 2025, focusing on distribution methods, volume, and disguising techniques. Key findings include the prevalence of ACRStealer, LummaC2, and Stealc Infostealers, with malware primarily distributed through SEO poisoning and compromised legitimate websites. The report highlights two significant trends: the abuse of Python scripts for malware distribution and the emergence of cryptocurrency-stealing malware using Tor. Distribution methods evolved from direct blog posts to leveraging legitimate websites and forums. The analysis also notes a shift in malware execution methods, with 65.8% distributed as EXE files and 34.2% using DLL Sideloading techniques. The report emphasizes the importance of vigilance against these evolving threats and provides detailed insights into the malware's behavior and infrastructure. Join the discussion | AlienVault OTX General | 01/16/2026, 20:33:26 UTC Added: 01/19/2026, 09:26:45 UTC |
A sophisticated campaign targeting Russian and Belarusian military personnel has been identified, using multi-stage infection chains and decoy documents. The attackers deploy OpenSSH and Tor bridges to establish covert remote access and lateral movement capabilities. The infection process involves PowerShell scripts, scheduled tasks for persistence, and the use of Tor hidden services to expose multiple local services. The campaign employs anti-analysis techniques and leverages obfuscated configurations for SSH and Tor. While attribution remains uncertain, the targeting and tactics are consistent with Eastern European-linked espionage activities focusing on defense and government sectors. Join the discussion | AlienVault OTX General | 10/31/2025, 21:01:40 UTC Added: 10/31/2025, 21:35:48 UTC |
Qilin ransomware is used for domain-wide encryption, and a ransom is then demanded for the decryption keys and/or to prevent the publication of the stolen data. Qilin affiliates are recruited from cybercrime forums to use the Qilin RaaS platform, which handles payload generation, the publication of stolen data, and ransom negotiations. Join the discussion | AlienVault OTX General | 10/08/2025, 16:25:25 UTC Added: 10/08/2025, 16:29:09 UTC |
In June 2025, Google's Salesforce instance was breached by UNC6040 & UNC6240 using vishing, OAuth app abuse, and anonymity layers. The attackers stole business data of small and medium-sized clients. A parallel attack by UNC6395 compromised Salesloft Drift's Salesforce integration, affecting hundreds of customers. Both incidents involved sophisticated social engineering, OAuth token abuse, and data exfiltration via TOR. The attacks are linked to the ShinyHunters group and share similarities with other high-profile breaches targeting various industries. The incidents highlight vulnerabilities in SaaS environments and the need for improved security measures, including OAuth governance, identity management, and proactive monitoring. Join the discussion | AlienVault OTX General | 09/03/2025, 15:30:53 UTC Added: 09/03/2025, 20:17:47 UTC |
The Efimer Trojan is spreading through compromised WordPress sites, malicious torrents, and email campaigns impersonating lawyers. It steals cryptocurrency by replacing wallet addresses in the clipboard and can execute additional malicious scripts. The Trojan communicates with its command-and-control server via the Tor network. It has additional capabilities to brute-force WordPress sites and harvest email addresses for further distribution. The malware primarily targeted users in Brazil, India, Spain, Russia, Italy, and Germany between October 2024 and July 2025, affecting over 5,000 Kaspersky users. Join the discussion | AlienVault OTX General | 08/08/2025, 14:04:44 UTC Added: 08/08/2025, 20:17:47 UTC |
Showing 1 to 6 of 6 results