Sunday, February 23, 2025
HomeCyber Security NewsTor Network Suffers IP Spoofing Attack Via Non-Exit Relays

Tor Network Suffers IP Spoofing Attack Via Non-Exit Relays

Published on

SIEM as a Service

Follow Us on Google News

In late October 2024, a coordinated IP spoofing attack targeted the Tor network, prompting abuse complaints and temporary disruptions.

While the attack affected non-exit relays and caused some relays to be taken offline, the overall impact on Tor users was limited.

Tor directory authorities, relay operators, and the Tor Project sysadmin team began receiving numerous abuse complaints alleging unauthorized port scanning activity.

The complaints were traced to a sophisticated IP spoofing attack. Attackers spoofed Tor-related IP addresses, particularly non-exit relays, to trigger automated abuse reports.

Attend a Free Webinar on How to Maximize Cybersecurity Program ROI

The goal appeared to be the disruption of the Tor network by getting key IPs blacklisted by major hosting providers.

The attack caused significant inconvenience for relay operators, many of whom had to deal with their hosting providers blocking or suspending their relays due to the complaints.

Data centers like OVH and Hetzner were affected, with Tor relays falsely implicated in malicious activity. Despite this, the attack did not compromise the privacy or security of Tor users.

The origin of the spoofed IP packets was identified thanks to a collaborative effort involving the Tor community, InterSecLab, and GreyNoise.

The attack was brought under control on November 7, 2024. Key contributions came from security expert Andrew Morris and Pierre Bourdon, a relay operator who provided critical analysis of the nature of the attack.

If your hosting provider is still blocking access to the Tor network, the Tor Project has provided resources to resolve these issues.

Relay operators are advised to use OONI Probe’s “Circumvention” test to check directory authority reachability and share relevant information with their hosting providers to clarify the situation.

This incident underscored the strength and resilience of the Tor community. Relay operators worked together, troubleshooting issues and sharing knowledge to keep the network running smoothly.

The Tor Project expressed gratitude to all those involved and encouraged continued cooperation to protect the network from future threats.

Run private, Real-time Malware Analysis in both Windows & Linux VMs. Get a 14-day free trial with ANY.RUN!

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

New Zhong Stealer Malware Exploit Zendesk to Attack Fintech and Cryptocurrency

A newly identified malware, dubbed Zhong Stealer, has emerged as a significant threat to...

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...

NSA Allegedly Hacked Northwestern Polytechnical University, China Claims

Chinese cybersecurity entities have accused the U.S. National Security Agency (NSA) of orchestrating a...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New Zhong Stealer Malware Exploit Zendesk to Attack Fintech and Cryptocurrency

A newly identified malware, dubbed Zhong Stealer, has emerged as a significant threat to...

SPAWNCHIMERA Malware Exploits Ivanti Buffer Overflow Vulnerability by Applying a Critical Fix

In a recent development, the SPAWNCHIMERA malware family has been identified exploiting the buffer...

Sitevision Auto-Generated Password Vulnerability Lets Hackers Steal Signing Key

A significant vulnerability in Sitevision CMS, versions 10.3.1 and earlier, has been identified, allowing...