Tor2Mine is a financially motivated cybercriminal group known for deploying cryptocurrency miners and additional malware on compromised systems. Its name derives from its use of Tor2web gateways to proxy command-and-control communications to Tor hidden services without requiring direct Tor connectivity. Tor2Mine is distinct from Rocke and 8220 Mining Group despite similarities in their mining tools and techniques. Documented activity dates to at least 2018, with renewed operations observed between January and June 2020 affecting at least six companies, including telecommunications and environmental consulting organizations. The group deploys XMRig and XMRigCC miners to monetize compromised computing resources. Its expanded malware arsenal includes the AZORult information stealer, Remcos remote-access tool, DarkVNC backdoor, and a clipboard cryptocurrency stealer, enabling credential theft, remote access, and cryptocurrency theft alongside mining. Tor2Mine uses PowerShell to retrieve follow-on payloads and Mshta to execute remotely hosted HTA scripts. Its delivery chains also employ JavaScript, VBScript, and batch scripts to reduce executable writes to disk. Its infrastructure has hosted 32-bit and 64-bit miners, EternalBlue and EternalRomance exploit implementations, an open-source TCP port scanner, and payload-downloading shellcode. The initial infection method in its early observed campaign was not established. No country of origin or state affiliation has been established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
8 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
64 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated cryptomining actor that resurfaced in 2020, using Tor2web-backed C2 infrastructure and expanding beyond XMRig cryptomining into credential theft and additional monetization via AZORult, Remcos, DarkVNC, and clipboard cryptocurrency stealing.
Conducts illicit cryptocurrency mining using tor2web gateways to communicate with hidden-service command-and-control infrastructure. The observed campaign downloaded PowerShell scripts and deployed XMRigCC miners. Talos connected it to earlier campaigns exploiting Apache Struts2 and Oracle WebLogic through similarities in infrastructure, scripts, payloads and mining destinations. The initial access mechanism for the directly observed tor2web campaign remained unknown.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.