Cybersecuritynews Torg Grabber Malware Evolves to Encrypted REST API for C2 Operations
Article Content
- •Torg Grabber has evolved from Telegram-based exfiltration to an encrypted REST API C2.
- •Over 334 samples of Torg Grabber have been compiled in just three months.
- •The malware targets credentials and sensitive information, posing a significant risk to users.
Torg Grabber, an information-stealing malware, has transitioned from using Telegram for data exfiltration to a more sophisticated encrypted REST API command-and-control (C2) channel, now utilizing Cloudflare for obfuscation. This malware, initially identified as a variant of Vidar, has demonstrated rapid evolution, with 334 samples compiled in just three months and over 40 confirmed operator tags found within its binaries. The malware primarily targets credentials and sensitive information, affecting various systems and users. The shift to a more secure C2 infrastructure indicates a significant advancement in its operational capabilities, raising concerns among cybersecurity professionals. The malware's development pace suggests a well-organized operation behind it, potentially posing a high risk to organizations that may fall victim to its tactics. Current status indicates ongoing monitoring and analysis as the threat landscape evolves.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Torg Grabber and Cloudflare in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…