Skip to main content
Mallory
MalwareRansomwareUsed by 11 actors

Tor

Tor is a free, open-source anonymity network and overlay network that enables anonymous communication through onion routing, encapsulating traffic in multiple layers of encryption and forwarding it through multiple relays before exit. It also supports hidden/onion services. In the provided content, Tor is repeatedly referenced as infrastructure or a client leveraged by adversaries rather than as a malware family itself. Reported malicious uses include anonymizing command-and-control traffic, facilitating data exfiltration, evading network monitoring and policy enforcement, routing brute-force activity, and creating hidden services to expose internal victim services externally. The content specifically notes Tor use by or in relation to APT28, APT29, APT40, Pawn Storm/Strontium, Gamaredon Group, GreyEnergy, Industroyer, Cyclops Blink, Medusa Group, FIN4, MacSpy, AsyncRAT, Attor, and WannaCry. CERT-UA reporting cited in the content describes an APT28 intrusion against Ukrainian critical energy infrastructure in which a victim host would download Tor from file.io and create hidden services redirecting traffic to internal domain controller and mail server ports. Another report describes nested ZIP and LNK-triggered PowerShell deploying Tor binaries on compromised Windows hosts. Splunk detection content highlights execution of tor.exe and related Tor Browser components on Windows as potentially suspicious because adversaries and insider threats may use Tor to anonymize C2 and exfiltration. Additional sample-specific details in the content include an embedded Tor client dropped to %TEMP%\skynet\tor.exe and launched with command-line arguments specifying local ControlPort 127.0.0.1:24616 and SocksPort 127.0.0.1:24615. Mentioned indicators and artifacts directly tied to Tor usage in the content include tor.exe, Tor Browser-related execution paths, and two onion addresses: s4k4ceiapwwgcm3mkb6e4diqecpo7kvdnfr5gg7sph7jjppqkvwwqtyd[.]onion and zn4zbhx2kx4jtcqexhr5rdfsj4nrkiea4nhqbfvzrtssakjpvdby73qd[.]onion.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

11 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Leviathan

Protocol tunneling and multi-hop proxies, including the use of Tor.

via cisa certus-cert.cisa.gov
APT28

"...з файлового сервісу file.io буде здійснено завантаження програми TOR та створення "прихованих" сервісів..."

via cert uacert.gov.ua
ZIRCONIUM

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
FIN4

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Medusa Group

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Lotus Blossom

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Gamaredon Group

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Volt Typhoon

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Ember Bear

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
Inception

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
APT29

The following analytic detects the execution of the TOR Browser and related TOR components on Windows endpoints by monitoring process creation activity. Adversaries and insider threats leverage TOR to anonymize command-and-control traffic, facilitate data exfiltration, and evade network monitoring and policy enforcement.

via splunk researchresearch.splunk.com
MITRE ATT&CK

Techniques & procedures

24 distinct techniques documented for this family, organized by ATT&CK tactic.

T1583.005BotnetEvidence1

"Use software which masks your IP address and other technology while researching via the internet (f example the Tor network, anonymize.net or Ipredator)."

T1588.002ToolEvidence2

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Initial Access

1 technique
T1133External Remote ServicesEvidence1

This tunnel provided the attacker remote access to the host system using the Terminal Services (TS), NetBIOS, and Server Message Block (SMB) services, while appearing to be traffic to legitimate websites.

Execution

3 techniques
T1053Scheduled Task/JobEvidence1

T1053 – Scheduled Task/Job Various scheduled tasks were executed.

T1059.001PowerShellEvidence1
TacticExecution

The attacker executed the PowerShell script C:\Program Files(x86)\Google\start.ps1 to install the TOR services and implement the “Sticky Keys” exploit.

T1059.003Windows Command ShellEvidence1
TacticExecution

Windows command shell (cmd.exe) was utilised extensively, particularly using Impacket, which relies on cmd.exe to facilitate command execution.

Persistence

3 techniques
T1053Scheduled Task/JobEvidence1

T1053 – Scheduled Task/Job Various scheduled tasks were executed.

T1133External Remote ServicesEvidence1

This tunnel provided the attacker remote access to the host system using the Terminal Services (TS), NetBIOS, and Server Message Block (SMB) services, while appearing to be traffic to legitimate websites.

T1543.003Windows ServiceEvidence3

T1543.003 - Create or Modify System Process: Windows Service Various Windows services were created across multiple compromised systems to establish remote access.

T1053Scheduled Task/JobEvidence1

T1053 – Scheduled Task/Job Various scheduled tasks were executed.

T1543.003Windows ServiceEvidence3

T1543.003 - Create or Modify System Process: Windows Service Various Windows services were created across multiple compromised systems to establish remote access.

Stealth

3 techniques
T1027Obfuscated Files or InformationEvidence1
TacticStealth

These tasks launched two disguised executables: operagx.exe, which was actually an OpenSSH daemon, and dropbox.exe, which was a Tor server. A third file, safari.exe, acted as an obfs4 traffic obfuscation plugin

T1070.006TimestompEvidence1
TacticStealth

The following files were dropped by the threat actor who had changed their created timestamp to historic values.

T1564Hide ArtifactsEvidence1
TacticStealth

He shows me a nickel. Then he slams it on the floor of his apartment. It pops open. Inside there is a tiny eight-gigabyte microSD memory card. It holds a copy of Tor.

Credential Access

2 techniques
T1040Network SniffingEvidence1

зная, в какой момент конкретный пользователь отправляет запросы через Tor... операторы программы могли при определенном везении сопоставить их по времени с заходами на сайты через подконтрольный узел.

T1557Adversary-in-the-MiddleEvidence1

В "Сайтэке" также планировали подменять трафик пользователям, попавшим в специально созданный узел. Сайты для таких пользователей могли выглядеть иначе, чем на самом деле.

Discovery

1 technique
T1040Network SniffingEvidence1

зная, в какой момент конкретный пользователь отправляет запросы через Tor... операторы программы могли при определенном везении сопоставить их по времени с заходами на сайты через подконтрольный узел.

Lateral Movement

2 techniques
T1021.001Remote Desktop ProtocolEvidence1

Critical local ports, including SMB port 445 and RDP port 3389, were mapped to a dark web Onion address... allowing the attacker to connect from anywhere in the world through the Tor network

T1021.002SMB/Windows Admin SharesEvidence1

Critical local ports, including SMB port 445 and RDP port 3389, were mapped to a dark web Onion address... allowing the attacker to connect from anywhere in the world through the Tor network

Collection

1 technique
T1557Adversary-in-the-MiddleEvidence1

В "Сайтэке" также планировали подменять трафик пользователям, попавшим в специально созданный узел. Сайты для таких пользователей могли выглядеть иначе, чем на самом деле.

T1001Data ObfuscationEvidence1

Obfs4 is a Pluggable Transport which modifies Tor traffic to communicate with a bridge.

T1071Application Layer ProtocolEvidence3

This trafficking of stolen data between producers, wholesalers and consumers is enabled by darknet markets, which are websites that resemble ordinary e-commerce websites but are accessible only using special browsers or authorization codes.

T1090ProxyEvidence3

ProxyChains could help you to run applications through a proxy server, which can help to hide your IP address and encrypt your internet traffic. However, ProxyChains alone does not provide anonymity on the internet. To achieve anonymity, we need a combination of ProxyChains and Tor.

T1090.002External ProxyEvidence1

WannaCry uses Tor for command and control traffic and routes a custom cryptographic protocol over the Tor circuit. Tor encapsulates traffic in multiple layers of encryption, using TLS by default.

T1090.003Multi-hop ProxyEvidence14

Using many proxy servers also did not guarantee that you wouldn’t get caught, but at least, that simple brainfuck game will make you a bit harder to find.

T1090.004Domain FrontingEvidence2

Mandiant has observed Russian nation-state attackers APT29 employing domain fronting techniques for stealthy backdoor access to victim environments for at least two years.

T1105Ingress Tool TransferEvidence2

Once the victim clicked the LNK file, the full attack toolkit deployed silently in the background while the real decoy PDF opened to keep the user distracted from the installation.

T1572Protocol TunnelingEvidence2

SSH tunnels were established to the IP address 128.254.207[.]157 from multiple compromised systems to create an encrypted channel that acted as a direct ingress point into the internal network for the threat actor.

T1573Encrypted ChannelEvidence4

Mandiant discovered that APT29 enabled a TOR hidden service that forwarded traffic from the TOR client to local ports 139, 445 and 3389 (NetBIOS, SMB and TS, respectively).

Exfiltration

1 technique
T1041Exfiltration Over C2 ChannelEvidence1

The center said the unknown perpetrator or perpetrators had published at least 300 patient records containing names and contact information using the anonymous Tor communication software.

INDICATORS OF COMPROMISE

IOCs tracked for this family

2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
2 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app9 years ago
hash.sha256●●●●●●●●●●●●View more in app9 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching2

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution11

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping24

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.