Skip to content
Torg Grabber Malware Evolves to Encrypted REST API for C2 Operations

Torg Grabber Malware Evolves to Encrypted REST API for C2 Operations

First seen 26 Mar 2026, 15:17 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 27, 2026 at 15:16 UTC
  • •Torg Grabber has evolved from Telegram-based exfiltration to an encrypted REST API C2.
  • •Over 334 samples of Torg Grabber have been compiled in just three months.
  • •The malware targets credentials and sensitive information, posing a significant risk to users.

Torg Grabber, an information-stealing malware, has transitioned from using Telegram for data exfiltration to a more sophisticated encrypted REST API command-and-control (C2) channel, now utilizing Cloudflare for obfuscation. This malware, initially identified as a variant of Vidar, has demonstrated rapid evolution, with 334 samples compiled in just three months and over 40 confirmed operator tags found within its binaries. The malware primarily targets credentials and sensitive information, affecting various systems and users. The shift to a more secure C2 infrastructure indicates a significant advancement in its operational capabilities, raising concerns among cybersecurity professionals. The malware's development pace suggests a well-organized operation behind it, potentially posing a high risk to organizations that may fall victim to its tactics. Current status indicates ongoing monitoring and analysis as the threat landscape evolves.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 195d ago How this analysis works

Timeline

2026-03-26
Torg Grabber's shift to encrypted REST API C2 reported
Recent
334 samples identified in a three-month period
Recent
Over 40 operator tags found in binaries

More articles in this cluster (2)

Following this threat?

Track Torg Grabber and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed