[tor-talk] Mirai Botnet Relocates To Onions

Mirimir mirimir at riseup.net
Sun Dec 18 05:59:37 UTC 2016


On 12/17/2016 10:11 PM, grarpamp wrote:
> https://www.bleepingcomputer.com/news/security/security-firms-almost-brought-down-massive-mirai-botnet/

<SNIP>

> Currently, to avoid further takedown attempts from similar security
> firms, BestBuy has started moving the botnet's command and control
> servers to Tor. "It's all good now. We don't need to pay thousands to
> ISPs and hosting. All we need is one strong server," the hacker said.
> "Try to shut down .onion 'domains' over Tor," he boasted, knowing that
> nobody can.

OK. However, it's not hard to scan for connections to Tor servers. And
you don't expect them for random devices. But maybe Mirai is setup to
use bridges.


More information about the tor-talk mailing list