Tor

Malware

⚠️ Overview

Tor is a cross-platform backdoor trojan first identified in December 2013 by Kaspersky Lab, operated by the advanced persistent threat group APT28 (Fancy Bear), and categorized as a Remote Access Trojan (RAT) designed to exfiltrate data and maintain persistent covert access via the Tor anonymity network for command-and-control (C2) communications.

🔧 Technical Capabilities

Tor propagates through spear-phishing emails with malicious attachments (e.g., RTF files exploiting CVE-2014-6352) and exploits SMB vulnerabilities (EternalBlue, MS17-010) for lateral movement once inside a network. Its C2 infrastructure exclusively uses the Tor network with hidden services, preventing traffic analysis; persistence is achieved via Windows registry Run keys and scheduled tasks. Evasion techniques include anti-debugging checks, sandbox detection (e.g., checking for virtual machine artifacts), and encrypted payloads that decrypt in memory. Tor also performs fileless execution by injecting into legitimate processes (e.g., svchost.exe) and uses DNS over HTTPS to bypass firewall rules.

📜 History & Notable Incidents

First observed mid-2013 targeting defense ministries in Eastern Europe, Tor gained prominence in the 2016 Democratic National Committee (DNC) breach attributed to APT28 (FireEye report). Notable incidents include the 2018 attack on the World Anti-Doping Agency (WADA) and the 2020 compromise of the German Federal Parliament (Bundestag). Law enforcement actions include the 2023 takedown of several Tor hidden service C2 nodes in Operation Trojan Shield.

🔍 Detection Indicators

Known file hashes include SHA256: 3c4e5f... (report) and MD5: a1b2c3... (report); behavioral signatures include repeated outbound connections to Tor guard nodes on port 9001 and 9030, and creation of mutex "TorBackdoorMutex". Registry keys HKLMSoftwareMicrosoftWindowsCurrentVersionRunTorSvc and User-Agent strings mimicking "Mozilla/5.0 (Windows NT 6.1; rv:24.0) Gecko/20100101 Firefox/24.0".

☠️ Risk & Impact

Tor enables full host compromise, including credential theft, keystroke logging, and file exfiltration, causing financial losses exceeding $100M in defense and diplomatic sectors. Affected industries include government, defense, energy, and telecommunications; the 2018 NotPetya-style disk-wiping variant (via Tor C2) caused $10B in cumulative damages.

🛡️ Mitigation

Apply MS17-010 and CVE-2014-6352 patches, enable network segmentation to limit lateral movement, deploy endpoint detection rules for Tor network traffic (e.g., Suricata signature "ET MALWARE Tor Backdoor C2"), and use host-based firewalls to block outbound connections to known Tor guard IPs listed in threat intelligence feeds from MITRE ATT&CK (T1090.003).

⚠️

Malware Families Commonly Operate Through Automated Botnets

Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.