Skip to content
New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

New Torg Grabber Stealer Moves From Telegram Exfiltration to Encrypted REST API C2

Cybersecuritynews •Tushar Subhra Dutta • March 26, 2026

A new Malware-as-a-Service (MaaS) credential stealer named Torg Grabber has surfaced, showing remarkable development pace over just three months. Starting with simple Telegram-based data exfiltration, it matured into a fully encrypted REST API command-and-control (C2) infrastructure. With 334 samples compiled in that short period and more than 40 confirmed operator tags found in the binaries, […]

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)