logo

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

ID: 7a72d703-6afb-5c68-bec8-143d27dbf7ea

STIX ID: report--7a72d703-6afb-5c68-bec8-143d27dbf7ea

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Torg Grabber is a fast‑maturing Malware-as-a-Service credential stealer observed from December 2025 to January 2026 that evolved from Telegram-based exfiltration to a ChaCha20/HMAC‑authenticated REST API C2 routed via Cloudflare; researchers identified 334 compiled samples, multiple operator tags linked to Russian-speaking cybercrime networks, broad targeting of Chromium and Firefox-family browsers (including crypto wallets and 2FA tools), and a multi-stage loader that achieves in‑memory execution and evasion—mitigations include avoiding cracked software, monitoring for suspicious PowerShell/BITS activity, detecting direct syscalls and in‑memory PE loading, and enforcing App‑Bound Encryption for Chromium processes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.