TorNet Backdoor: A Stealthy Cyber Threat Targeting Poland and Beyond
ID: bc58835f-0347-5628-bbf7-489096b4af76
STIX ID: report--bc58835f-0347-5628-bbf7-489096b4af76
Feed Name: SOCRadar Blog
TorNet Backdoor is an active, financially motivated phishing campaign observed since at least July 2024 that targets users primarily in Poland and Germany. Attackers deliver .tgz attachments or links that install a Tor‑connected backdoor enabling encrypted command-and-control, data theft, and secondary malware deployment; the report provides IoCs (hashes, domains, URLs), mitigation guidance (user training, email filtering, network traffic analysis, endpoint protection, patching), and attribution indicators pointing to a criminal actor exploiting Tor for stealth.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
