Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

New Variant of Gafgyt Uses Tor and is Potentially Connected to the Necro Botnet Group

released on 2021-03-05 @ 04:23:38 PM
Since February 15, 2021, 360Netlab's BotMon system has continuously detected a new variant of the Gafgyt family, which uses Tor for C2 communication to hide the real C2 and encrypts sensitive strings in the samples. This is the first time we found a Gafgyt variant using the Tor mechanism, so we named the variant Gafgyt_tor. Further analysis revealed that the family is closely related to the Necro family we made public in January, and is behind the same group of people, the so-called keksec group. In this blog, we will introduce Gafgyt_tor and sort out other recent botnets operated by this group.