logo

New TorNet backdoor seen in widespread campaign

ID: 09eb3a8e-e364-5155-97f3-f846d4146e79

STIX ID: report--09eb3a8e-e364-5155-97f3-f846d4146e79

Feed Name: Cisco Talos

Threat Score
72/100

Date Published: 2025-01-28

Date Updated: 2026-04-27

Author: Chetan Raghuprasad

...
...

Cisco Talos identified a financially motivated phishing campaign (since July 2024) targeting mainly Polish and German users that delivers multiple Windows malware families — including an AES-encrypted PureCrypter loader and a new .NET backdoor called TorNet — via .tgz email attachments; the actors use reflective loading, anti-analysis and anti-VM checks, disable/re-enable the network (ipconfig /release and /renew) to evade cloud AV, establish persistence via Run keys and scheduled tasks that run even on low battery, route backdoor C2 traffic through the Tor network, and support execution of arbitrary .NET assemblies from C2; the report includes IOCs, Snort SIDs, and ClamAV detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.