Tor is a free, open-source anonymity network and overlay network that enables anonymous communication through onion routing, encapsulating traffic in multiple layers of encryption and forwarding it through multiple relays before exit. It also supports hidden/onion services. In the provided content, Tor is repeatedly referenced as infrastructure or a client leveraged by adversaries rather than as a malware family itself. Reported malicious uses include anonymizing command-and-control traffic, facilitating data exfiltration, evading network monitoring and policy enforcement, routing brute-force activity, and creating hidden services to expose internal victim services externally. The content specifically notes Tor use by or in relation to APT28, APT29, APT40, Pawn Storm/Strontium, Gamaredon Group, GreyEnergy, Industroyer, Cyclops Blink, Medusa Group, FIN4, MacSpy, AsyncRAT, Attor, and WannaCry. CERT-UA reporting cited in the content describes an APT28 intrusion against Ukrainian critical energy infrastructure in which a victim host would download Tor from file.io and create hidden services redirecting traffic to internal domain controller and mail server ports. Another report describes nested ZIP and LNK-triggered PowerShell deploying Tor binaries on compromised Windows hosts. Splunk detection content highlights execution of tor.exe and related Tor Browser components on Windows as potentially suspicious because adversaries and insider threats may use Tor to anonymize C2 and exfiltration. Additional sample-specific details in the content include an embedded Tor client dropped to %TEMP%\skynet\tor.exe and launched with command-line arguments specifying local ControlPort 127.0.0.1:24616 and SocksPort 127.0.0.1:24615. Mentioned indicators and artifacts directly tied to Tor usage in the content include tor.exe, Tor Browser-related execution paths, and two onion addresses: s4k4ceiapwwgcm3mkb6e4diqecpo7kvdnfr5gg7sph7jjppqkvwwqtyd[.]onion and zn4zbhx2kx4jtcqexhr5rdfsj4nrkiea4nhqbfvzrtssakjpvdby73qd[.]onion.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"...з файлового сервісу file.io буде здійснено завантаження програми TOR та створення "прихованих" сервісів..."
The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.
The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.
The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.
The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
The malware is then installed to the hardcoded path %ProgramFiles(x86)%\Adobe\Acrobat Reader DC\Reader\update and uses legitimate Adobe Acrobat Reader executable names for the bundled Tor executable and its own.
Step 2: Collect System Information The DGA sample only collects two pieces of information: The number of processors of the infected system ... The Tor-based downloader generates a much more detailed system report, by running the following commands: cmd.exe /c "(wmic computersystem get /format:list) ... wmic cpu ... memorychip ... Win32_VideoController ... AntiVirusProduct ... nicconfig ... os ... Win32_SystemEnclosure
...форвардинг локальних мережевих портів (зокрема, 445, 3389, 22) на віддалений сервер...
...форвардинг локальних мережевих портів (зокрема, 445, 3389, 22) на віддалений сервер...
The central component of the threat is the bundled Tor client, which routes communication over localhost:9050 and resolves destination domains to reduce DNS visibility and hide its C&C location.
All communication to the C&C is done through Tor at jg4rli4xoagvvmw47fr2bnnfu7t2epj6owrgyoee7daoh4gxvbt3bhyd.onion using the HTTP protocol.
A further module allowed the malware to create a giant Tor network comprising the many compromised systems. This network potentially allowed attackers to disguise the ultimate destination of data stolen from other compromised systems, or the country of origin of attacks against systems.
WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit. Tor encapsulates traffic in multiple layers of encryption, using TLS by default.
The malware then tries to download the payload from two domains on an alternating basis: asxe4d2fmz7ji5ux.onion dyvt2mleg33f6zdb.onion | The Tor-based downloader comes with Tor version 0.3.3.7, which it installs to %LOCALAPPDATA%\Temp\ . It then tries to contact http://www.google.com over Proxy 127.0.0.1:9050 to see if Tor is running.
Mandiant has observed Russian nation-state attackers APT29 employing domain fronting techniques for stealthy backdoor access to victim environments for at least two years.
SSH tunnels were established to the IP address 128.254.207[.]157 from multiple compromised systems to create an encrypted channel that acted as a direct ingress point into the internal network for the threat actor.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
TOR is used to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement on Windows endpoints.
Tor is referenced as having an associated JA3 hash; it can be used to anonymize attacker communications and infrastructure.
Tor is an open-source anonymity network designed to conceal users' identities and online activity from surveillance and traffic analysis. It routes internet traffic through a global network of relays, using layered encryption (onion routing) to provide privacy and resist censorship. Tor is used for both legitimate privacy needs and illicit activities, and is the foundation for accessing .onion services (the 'dark web').
A legitimate Tor client embedded and dropped by the Skynet sample to establish a local SOCKS proxy and control port for anonymized communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.