Tor
MITRE ATT&CK: S0183 View on attack.mitre.org
Aliases: Tor
- Operating systems
- linux, windows, macos
- Related IoCs
- 78 (14 malicious)
- Last IoC activity
- 2026-09-01 23:58:01
- Profile updated
- 2026-07-07 15:32:51
Context
Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.
Recent IoC activity
14 malicious indicators in Maltiverse are attributed to Tor (S0183). The 14 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| IP address | 193.11.114.45 | 2026-09-02 | 6 |
| IP address | 212.47.233.86 | 2026-09-02 | 6 |
| IP address | 204.8.156.142 | 2026-09-02 | 17 |
| IP address | 185.220.101.9 | 2026-09-02 | 22 |
| IP address | 171.25.193.77 | 2026-09-02 | 28 |
| IP address | 193.11.114.43 | 2026-09-01 | 6 |
| IP address | 66.111.2.20 | 2026-09-01 | 7 |
| IP address | 188.40.128.246 | 2026-08-31 | 6 |
| IP address | 192.87.28.82 | 2026-08-30 | 7 |
| file sample | torbrowser-install-8.0.6_pl.exe | 2026-04-17 | 1 |
| file sample | torbrowser-install-8.0.4_en-US.exe | 2026-04-04 | 1 |
| file sample | torbrowser-install-8.0.6_es-ES.exe | 2025-12-05 | 1 |
| hostname | dcky6u1m8u6el.cloudfront.net | 2025-09-23 | 2 |
| file sample | torbrowser-install-8.0.7_ru.exe | 2025-09-01 | 1 |
Detection coverage
- 3 Sigma rules
Malware & tools used
- Asymmetric Cryptography (attack-pattern)
- Multi-hop Proxy (attack-pattern)
Used by threat actors
- FLORAHOX Activity (campaign)
- Operation Wocao (campaign)
- CostaRicto (campaign)
- 2025 Poland Wiper Attacks (campaign)
- Salesforce Data Exfiltration (campaign)
- Water Galura (threat-actor)
- Scattered Spider (threat-actor)
- INC Ransom (threat-actor)
- APT28 (threat-actor)
- APT29 (threat-actor)
- Leviathan (threat-actor)
- ShinyHunters (threat-actor)
Reports & references
- dtic.mil — A465464 (report)
- MITRE ATT&CK — S0183 (report)