KAX17

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
organization
Actor type
unknown
Profile updated
2026-07-07 12:08:51

Context

KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primarily as entry and middle points. Their main objective appears to be collecting information on Tor users and mapping their routes within the network. Despite efforts to remove their servers, KAX17 has shown resilience and continues to operate.

Reports & references

  • malwarebytes.com — Amp (report)
  • therecord.media — A Mysterious Threat Actor Is Running Hundreds Of Malicious Tor Relays (report)
  • darknetlive.com — Who Is Responsible For Running Hundreds Of Malicious Tor Relays (report)
  • nusenu.medium.com — Is Kax17 Performing De Anonymization Attacks Against Tor Users 42E566Defce8 (report)

External references