Torg Grabber Malware Evolves to Encrypted REST API for C2 Operations

Torg Grabber Malware Evolves to Encrypted REST API for C2 Operations

First seen 26 Mar 2026, 15:17 UTC GbhackersCybersecuritynews 80% similarity 66.5

Article Content

Browse articles
ThreatCluster

Torg Grabber, an information-stealing malware, has transitioned from using Telegram for data exfiltration to a more sophisticated encrypted REST API command-and-control (C2) channel, now utilizing Cloudflare for obfuscation. This malware, initially identified as a variant of Vidar, has demonstrated rapid evolution, with 334 samples compiled in just three months and over 40 confirmed operator tags found within its binaries. The malware primarily targets credentials and sensitive information, affecting various systems and users. The shift to a more secure C2 infrastructure indicates a significant advancement in its operational capabilities, raising concerns among cybersecurity professionals. The malware's development pace suggests a well-organized operation behind it, potentially posing a high risk to organizations that may fall victim to its tactics. Current status indicates ongoing monitoring and analysis as the threat landscape evolves.

Key Points: • Torg Grabber has evolved from Telegram-based exfiltration to an encrypted REST API C2. • Over 334 samples of Torg Grabber have been compiled in just three months. • The malware targets credentials and sensitive information, posing a significant risk to users.

ThreatCluster AI How this analysis works

Timeline

2026-03-26
Torg Grabber's shift to encrypted REST API C2 reported
Recent
334 samples identified in a three-month period
Recent
Over 40 operator tags found in binaries

Community

Browse all →

Tracked Entities in This Story