Monday, April 28, 2025
HomeTorOver 25% of Tor Exit Nodes Intercept Traffic to Carry Out Spying...

Over 25% of Tor Exit Nodes Intercept Traffic to Carry Out Spying Activities

Published on

SIEM as a Service

Follow Us on Google News

An unknown threat actors using the malicious exit nodes to the Tor network for over a year (more than 16 months) simply to intercept the traffic and carry out SSL-stripping attacks on the users who are visiting the websites related to the cryptocurrency.

Now many of you might be thinking that what is SSL-stripping? It is a method through which the attackers downgrade a connection from secure HTTPS to plain HTTP.

Here the attacks became known back in August 2020, all thanks to a security researcher known as “Nusenu,” who is also the operator of the Tor exit node. 

- Advertisement - Google News

At the time, it was reported that the attacks began in January last year, and at the height of the operation, the attackers controlled approximately four hundred malicious Tor exit nodes.

New Complicated Attack 

However, according to the report that summited by Nusenu over Medium, during the attacks, the attackers changed the addresses of cryptocurrency wallets with their own to intercept transactions.

Despite the reporting last year, the threat actors are still operating their attacks. As in February 2021, attacks hit 27% of malicious Tor exit nodes, although the second wave of attacks was noticed and neutralized.

But, after the malicious infrastructure had been active for several weeks. The main reason for the success of this operation is that the attackers added malicious nodes in small numbers, quietly creating an impressive infrastructure.

Apart from this, since May Nusenu has been reporting the malicious exit relays to the admins of the Tor network. Even he also claimed that the capabilities of the attackers have been decreased dramatically just after the latest takedown that took place on June 21.

In early May, the attackers tried to simultaneously return back online all the disconnected servers, that couldn’t go unnoticed. Here, the attack was discovered just a day after the number of Tor exit nodes skyrocketed from 1500 to more than 2500.

So, instead of shutting down over 1,000 malicious servers, still the attackers have 4-6% of Tor’s power output under their control. Moreover, Nusenu noted that, after the SSL-stripping attack, the attackers download modifications, but what they exactly do is still not clear.

In 2018, a Similar Attack Took Place

The cybersecurity specialists claimed that in 2018 a similar type of attack took place, but at that time Tor exit nodes were not targeted. Instead of Tor nodes, the attackers targeted the Tor-to-web (Tor2Web) proxies.

Moreover, the Tor-to-web (Tor2Web) proxies are the public websites that allow normal users to access the .onion websites that are only accessible through the Tor Browser.

During this operation, Proofpoint, a US security firm who reported that an unknown operator of the Tor-to-web proxy has been replacing the Bitcoin addresses for the users silently who are seeking to pay the ransom demands on the ransomware payment portals.

As a result, the threat actors who are in the middle are silently looting the ransom payments of the users, and leaving them aside without a decryption key, even after paying the ransom amount.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

How To Use Digital Forensics To Strengthen Your Organization’s Cybersecurity Posture

Digital forensics has become a cornerstone of modern cybersecurity strategies, moving beyond its traditional...

Building A Strong Compliance Framework: A CISO’s Guide To Meeting Regulatory Requirements

In the current digital landscape, Chief Information Security Officers (CISOs) are under mounting pressure...

Two Systemic Jailbreaks Uncovered, Exposing Widespread Vulnerabilities in Generative AI Models

Two significant security vulnerabilities in generative AI systems have been discovered, allowing attackers to...

New AI-Generated ‘TikDocs’ Exploits Trust in the Medical Profession to Drive Sales

AI-generated medical scams across TikTok and Instagram, where deepfake avatars pose as healthcare professionals...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Kaspersky Shares 12 Essential Tips for Messaging App Security and Privacy

In an era where instant messaging apps like WhatsApp, Telegram, Signal, iMessage, Viber, and...

Tor Browser 14.0.8 Emergency Release for Windows Users

The Tor Project has swiftly released an emergency update for the Tor Browser, 14.0.8,...

Top 10 Best Penetration Testing Companies in 2025

Penetration testing companies play a vital role in strengthening the cybersecurity defenses of organizations...