CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2
ID: c87c1495-b182-5f54-9764-edd60d08ba2c
STIX ID: report--c87c1495-b182-5f54-9764-edd60d08ba2c
Feed Name: CosmicBytez Labs
Threat Score
**CryptoBandits** is a dual-function malware family that combines credential and cryptocurrency wallet theft with a persistent backdoor; it establishes a local SOCKS5 proxy on infected hosts and routes all command-and-control and exfiltration traffic over the Tor network, making network-level detection and IP-based blocking ineffective—recommended response for confirmed infections is full system reimaging and credential rotation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
