TorNet Backdoor: Stealthy Phishing Campaign Hits Poland and Germany

Amber | Attack Report
Download PDF

A financially motivated threat actor has been orchestrating a persistent phishing campaign since at least July 2024, primarily targeting users in Poland and Germany. The attacker employs various payloads, including a previously undocumented backdoor dubbed TorNet, which is deployed via the PureCrypter malware. Once executed, TorNet stealthily connects the victim’s machine to the TOR network, enabling covert command-and-control (C2) communications while evading detection.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox