Tor

MITRE ATT&CK: S0183 View on attack.mitre.org

Aliases: Tor

Operating systems
linux, windows, macos
Related IoCs
78 (14 malicious)
Last IoC activity
2026-09-01 23:58:01
Profile updated
2026-07-07 15:32:51

Context

Tor is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. Tor utilizes "Onion Routing," in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.

Recent IoC activity

14 malicious indicators in Maltiverse are attributed to Tor (S0183). The 14 most recently updated:

TypeIndicatorUpdatedSources
IP address 193.11.114.45 2026-09-02 6
IP address 212.47.233.86 2026-09-02 6
IP address 204.8.156.142 2026-09-02 17
IP address 185.220.101.9 2026-09-02 22
IP address 171.25.193.77 2026-09-02 28
IP address 193.11.114.43 2026-09-01 6
IP address 66.111.2.20 2026-09-01 7
IP address 188.40.128.246 2026-08-31 6
IP address 192.87.28.82 2026-08-30 7
file sample torbrowser-install-8.0.6_pl.exe 2026-04-17 1
file sample torbrowser-install-8.0.4_en-US.exe 2026-04-04 1
file sample torbrowser-install-8.0.6_es-ES.exe 2025-12-05 1
hostname dcky6u1m8u6el.cloudfront.net 2025-09-23 2
file sample torbrowser-install-8.0.7_ru.exe 2025-09-01 1

Detection coverage

  • 3 Sigma rules

Malware & tools used

  • Asymmetric Cryptography (attack-pattern)
  • Multi-hop Proxy (attack-pattern)

Used by threat actors

Reports & references

  • dtic.mil — A465464 (report)
  • MITRE ATT&CK — S0183 (report)

External references