logo

CryptoBandits Malware Doubles as a Backdoor, Abuses Tor for Stealthy C2

ID: c87c1495-b182-5f54-9764-edd60d08ba2c

STIX ID: report--c87c1495-b182-5f54-9764-edd60d08ba2c

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

**CryptoBandits** is a dual-function malware family that combines credential and cryptocurrency wallet theft with a persistent backdoor; it establishes a local SOCKS5 proxy on infected hosts and routes all command-and-control and exfiltration traffic over the Tor network, making network-level detection and IP-based blocking ineffective—recommended response for confirmed infections is full system reimaging and credential rotation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.