Skip to content
Torg Grabber Malware Shifts from Telegram Exfiltration to Encrypted REST API for C2

Torg Grabber Malware Shifts from Telegram Exfiltration to Encrypted REST API for C2

Gbhackers •Mayura Kathir • March 26, 2026

A fast-evolving information‑stealing malware dubbed “Torg Grabber” that has shifted from simple Telegram‑based exfiltration to a hardened, encrypted REST API command‑and‑control (C2) channel fronted by Cloudflare. The operation surfaced when a 747 KB 64‑bit sample initially tagged as Vidar was found to be fundamentally different from known Vidar builds, exposing an internal debug string “grabber […]

Extracted Entities

Attack Types (1)

Companies (1)

Malware (2)

Platforms (1)