logo

Torg Grabber Malware Shifts from Telegram Exfiltration to Encrypted REST API for C2

ID: 714c6e80-c4d5-5db7-b9c9-b0296c7b8f80

STIX ID: report--714c6e80-c4d5-5db7-b9c9-b0296c7b8f80

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-03-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

Torg Grabber is a fast‑evolving information‑stealing malware family deployed via pirated installers and polymorphic loaders that keeps its core stealer off disk; it has transitioned from Telegram-based exfiltration to an encrypted HTTPS REST API C2 fronted by Cloudflare and operated as a Malware‑as‑a‑Service. The stealer reflectively maps a PE into memory, bypasses browser ABE to recover AES master keys, harvests credentials/cookies from many Chromium and Firefox variants, extracts cryptocurrency wallets and extension data, and fingerprints hosts during registration; researchers mapped multiple rotating C2 domains, operator tags linking to Russian‑language cybercrime accounts, and recommended detections such as TLS inspection and REST‑pattern monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.