logo

TorNet Backdoor: A Stealthy Cyber Threat Targeting Poland and Beyond

ID: bc58835f-0347-5628-bbf7-489096b4af76

STIX ID: report--bc58835f-0347-5628-bbf7-489096b4af76

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2025-01-29

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

TorNet Backdoor is an active, financially motivated phishing campaign observed since at least July 2024 that targets users primarily in Poland and Germany. Attackers deliver .tgz attachments or links that install a Tor‑connected backdoor enabling encrypted command-and-control, data theft, and secondary malware deployment; the report provides IoCs (hashes, domains, URLs), mitigation guidance (user training, email filtering, network traffic analysis, endpoint protection, patching), and attribution indicators pointing to a criminal actor exploiting Tor for stealth.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.