An unknown threat actor managed to control more than 27% of the entire Tor network exit capacity in early February 2021, a new study on the dark web infrastructure revealed.
"The entity attacking Tor users is actively exploiting tor users since over a year and expanded the scale of their attacks to a new record level," an independent security researcher who goes by the name nusenu said in a write-up published on Sunday. "The average exit fraction this entity controlled was above 14% throughout the past 12 months."
It's the latest in a series of efforts undertaken to bring to light malicious Tor activity perpetrated by the actor since December 2019. The attacks, which are said to have begun in January 2020, were first documented and exposed by the same researcher in August 2020.
Tor is open-source software for enabling anonymous communication on the Internet. It obfuscates the source and destination of a web request by directing network traffic through a series of relays in order to mask a user's IP address and location and usage from surveillance or traffic analysis. While middle relays typically take care of receiving traffic on the network and passing it along, an exit relay is the final node that Tor traffic passes through before it reaches its destination.
Exit nodes on the Tor network have been subverted in the past to inject malware such as OnionDuke, but this is the first time a single unidentified actor has managed to control such a large fraction of Tor exit nodes.
The hacking entity maintained 380 malicious Tor exit relays at its peak in August 2020, before the Tor directory authorities intervened to cull the nodes from the network, following which the activity once again crested early this year, with the attacker attempting to add over 1,000 exit relays in the first week of May. All the malicious Tor exit relays detected during the second wave of the attacks have since been removed.
The main purpose of the attack, according to nusenu, is to carry out "person-in-the-middle" attacks on Tor users by manipulating traffic as it flows through its network of exit relays. Specifically, the attacker appears to perform what's called SSL stripping to downgrade traffic heading to Bitcoin mixer services from HTTPS to HTTP in an attempt to replace bitcoin addresses and redirect transactions to their wallets instead of the user-provided bitcoin address.
"If a user visited the HTTP version (i.e. the unencrypted, unauthenticated version) of one of these sites, they would prevent the site from redirecting the user to the HTTPS version (i.e. the encrypted, authenticated version) of the site," the maintainers of Tor Project explained last August. "If the user didn't notice that they hadn't ended up on the HTTPS version of the site (no lock icon in the browser) and proceeded to send or receive sensitive information, this information could be intercepted by the attacker."
To mitigate such attacks, the Tor Project outlined a number of recommendations, including urging website administrators to enable HTTPS by default and deploy .onion sites to avoid exit nodes, adding it's working on a "comprehensive fix" to disable plain HTTP in Tor Browser.
"The risk of being the target of malicious activity routed through Tor is unique to each organization," the U.S. Cybersecurity Security and Infrastructure Security Agency (CISA) said in an advisory in July 2020. "An organization should determine its individual risk by assessing the likelihood that a threat actor will target its systems or data and the probability of the threat actor's success given current mitigations and controls."
"Organizations should evaluate their mitigation decisions against threats to their organization from advanced persistent threats (APTs), moderately sophisticated attackers, and low-skilled individual hackers, all of whom have leveraged Tor to carry out reconnaissance and attacks in the past," the agency added.
Read the original post:
Over 25% Of Tor Exit Relays Spied On Users' Dark Web Activities - The Hacker News
- Tor - Official Site [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Tor Browser (M-S0FT) - Video [Last Updated On: April 26th, 2014] [Originally Added On: April 26th, 2014]
- Downloading torrents in utorrent using tor browser - Video [Last Updated On: April 27th, 2014] [Originally Added On: April 27th, 2014]
- Tor Browser installieren [Tutorial deutsch] - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- TOR BROWSER KURULUM+KULLANIM - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- tor browser descargar e instalar - Video [Last Updated On: May 1st, 2014] [Originally Added On: May 1st, 2014]
- Entering the Deep Web-Deep Web Url link (2014) - Video [Last Updated On: May 6th, 2014] [Originally Added On: May 6th, 2014]
- Red Onion Tor Browser for iPhone - Video [Last Updated On: May 10th, 2014] [Originally Added On: May 10th, 2014]
- working referral link to agora hidden market place -new url ( onion site ) - Video [Last Updated On: May 12th, 2014] [Originally Added On: May 12th, 2014]
- Tor Browser Free Download/Install|Free Latest Version|64/32 bit Windows|2014 - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- how to install TOR Browser On LINUX - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- Grams Darknet black market search engine demo - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- How to Install the New Tor Browser in Kali Linux - Video [Last Updated On: May 18th, 2014] [Originally Added On: May 18th, 2014]
- How to download and use Tor browser [4K] - Video [Last Updated On: May 20th, 2014] [Originally Added On: May 20th, 2014]
- Free App Lets the Next Snowden Send Big Files Securely and Anonymously [Last Updated On: May 22nd, 2014] [Originally Added On: May 22nd, 2014]
- How to get free 7 day trials for XBL works as of May 2014 - Video [Last Updated On: May 23rd, 2014] [Originally Added On: May 23rd, 2014]
- Free Access to Deep Web (HIdden Wikki)(Tor Browser)-free 2014 - Video [Last Updated On: May 27th, 2014] [Originally Added On: May 27th, 2014]
- Federal Cybersecurity Director Found Guilty on Child Porn Charges [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Cybersecurity official uses Tor but still gets caught with child porn [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Softonic - Tor Browser - Download [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- What is the Tor Browser? - Tor Project: Anonymity Online [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Tor Browser - Problem Connecting? [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Review: Tor Browser Bundle lets you browse in anonymity ... [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Guide to using the Tor Browser Bundle for secure communication - Video [Last Updated On: August 31st, 2014] [Originally Added On: August 31st, 2014]
- Hack-Bypass Hotspot (Mikrotik) With Tor Browser - Video [Last Updated On: September 3rd, 2014] [Originally Added On: September 3rd, 2014]
- Using tor-browser on ubuntu 14.04 LTS - Video [Last Updated On: September 7th, 2014] [Originally Added On: September 7th, 2014]
- Download Tor Browser Bundle 3 6 5 For Win, Mac, Linux - Video [Last Updated On: September 8th, 2014] [Originally Added On: September 8th, 2014]
- Browse Anonymously, Browse Safely - The App Center [Last Updated On: September 11th, 2014] [Originally Added On: September 11th, 2014]
- Tor browser NOT SAFE without this quick step - Video [Last Updated On: September 12th, 2014] [Originally Added On: September 12th, 2014]
- Tor Browser for iOS - Free download and software reviews ... [Last Updated On: September 14th, 2014] [Originally Added On: September 14th, 2014]
- Comcast Denies It Will Cut Off Customers Who Use Tor, The Web Browser For Criminals (CMCSA) [Last Updated On: September 15th, 2014] [Originally Added On: September 15th, 2014]
- Comcast calls rumor that it disconnects Tor users wildly inaccurate [Last Updated On: September 15th, 2014] [Originally Added On: September 15th, 2014]
- Why a thinly sourced, unverified report about Comcast has the Web in an uproar [Last Updated On: September 16th, 2014] [Originally Added On: September 16th, 2014]
- Drier: Is Comcast really blocking anonymous Internet browser Tor? [Last Updated On: September 19th, 2014] [Originally Added On: September 19th, 2014]
- Guns, drugs and freedom: the great dark net debate [Last Updated On: September 19th, 2014] [Originally Added On: September 19th, 2014]
- Download and Install Tor Browser Bundle - Video [Last Updated On: September 24th, 2014] [Originally Added On: September 24th, 2014]
- install tor browser for kali linux 1.0.9 - Video [Last Updated On: September 27th, 2014] [Originally Added On: September 27th, 2014]
- TOR Browser: Safe to use 2014? - Yahoo Answers [Last Updated On: September 28th, 2014] [Originally Added On: September 28th, 2014]
- Alex Jones Interviews Creator of TOR Browser- Infowars September 2014 - Video [Last Updated On: September 28th, 2014] [Originally Added On: September 28th, 2014]
- Tor Executive Director Hints At Firefox Integration [Last Updated On: September 30th, 2014] [Originally Added On: September 30th, 2014]
- Dreaming of a Tor Button for Firefox [Last Updated On: September 30th, 2014] [Originally Added On: September 30th, 2014]
- Install tor browser on kali linux - Video [Last Updated On: September 30th, 2014] [Originally Added On: September 30th, 2014]
- How to install TOR browser bundle on sparkylinux 32bit - Video [Last Updated On: September 30th, 2014] [Originally Added On: September 30th, 2014]
- Firefox could be adding built-in Tor support for improved private browsing [Last Updated On: October 2nd, 2014] [Originally Added On: October 2nd, 2014]
- Tor Browser Bundle: Download & Start - Tutorial deutsch - Video [Last Updated On: October 3rd, 2014] [Originally Added On: October 3rd, 2014]
- With This Tiny Box, You Can Anonymize Everything You Do Online [Last Updated On: October 13th, 2014] [Originally Added On: October 13th, 2014]
- Tor Browser Cheat TankPit - Video [Last Updated On: October 13th, 2014] [Originally Added On: October 13th, 2014]
- Anonabox Promises Total Online Anonymity That's Easy, Open Source, and Cheap [Last Updated On: October 14th, 2014] [Originally Added On: October 14th, 2014]
- This tiny box anonymises all your online actions [Last Updated On: October 14th, 2014] [Originally Added On: October 14th, 2014]
- Anonabox promises a portable, streamlined way to use Tor to hide your online tracks [Last Updated On: October 14th, 2014] [Originally Added On: October 14th, 2014]
- Investors flock to tiny device that promises online anonymity [Last Updated On: October 16th, 2014] [Originally Added On: October 16th, 2014]
- How to run all your Internet's programs thru Tor Browser - Video [Last Updated On: October 16th, 2014] [Originally Added On: October 16th, 2014]
- Tails 1.2 : Released with Tor Browser 4.0 - Video [Last Updated On: October 20th, 2014] [Originally Added On: October 20th, 2014]
- Tor Browser 4.0 is released | The Tor Blog [Last Updated On: October 25th, 2014] [Originally Added On: October 25th, 2014]
- Access Blocked site using Tor Browser and chrome [2014] - Video [Last Updated On: October 27th, 2014] [Originally Added On: October 27th, 2014]
- Be Anonymous Online : TOR Browser - Video [Last Updated On: October 27th, 2014] [Originally Added On: October 27th, 2014]
- Menggunakan TOR Browser - Video [Last Updated On: October 29th, 2014] [Originally Added On: October 29th, 2014]
- Facebook Just Created a Custom Tor Link and That's Awesome [Last Updated On: October 31st, 2014] [Originally Added On: October 31st, 2014]
- How to Use Deep Web Using Tor Browser - Video [Last Updated On: October 31st, 2014] [Originally Added On: October 31st, 2014]
- Setup Tor Browser on Mac OS 10 - Video [Last Updated On: October 31st, 2014] [Originally Added On: October 31st, 2014]
- Facebook opens up to Tor users with new secure .onion address [Last Updated On: November 1st, 2014] [Originally Added On: November 1st, 2014]
- How to use the Tor browser and the Open PGP applet - Video [Last Updated On: November 1st, 2014] [Originally Added On: November 1st, 2014]
- Facebookcorewwwi.onion ( Preview ) - Video [Last Updated On: November 2nd, 2014] [Originally Added On: November 2nd, 2014]
- How to use Tor for Facebook (Windows, Mac & Linux) [Last Updated On: November 4th, 2014] [Originally Added On: November 4th, 2014]
- Tor Browser Bundle - Secure your Web surfing - [Free Download] - Video [Last Updated On: November 5th, 2014] [Originally Added On: November 5th, 2014]
- The Law Scores a Victory Against Dark Net Denizens [Last Updated On: November 8th, 2014] [Originally Added On: November 8th, 2014]
- Tor Browser New 4 - Video [Last Updated On: November 8th, 2014] [Originally Added On: November 8th, 2014]
- How to (Install- Enable) Flash Player on Tor Browser - Video [Last Updated On: November 9th, 2014] [Originally Added On: November 9th, 2014]
- Tor Browser New 2 - Video [Last Updated On: November 9th, 2014] [Originally Added On: November 9th, 2014]
- Tor Browser New 1 - Video [Last Updated On: November 9th, 2014] [Originally Added On: November 9th, 2014]
- Developer edition and privacy are Firefoxs 10th birthday present for the world [Last Updated On: November 11th, 2014] [Originally Added On: November 11th, 2014]
- Easily Install Tor Browser 4.0.1 via PPA in Linux Mint 17 - Video [Last Updated On: November 11th, 2014] [Originally Added On: November 11th, 2014]
- Better Tor-gether? Mozillla bids to bring anonymous browsing to the masses [Last Updated On: November 12th, 2014] [Originally Added On: November 12th, 2014]
- How to connect Tor Browser to Country-specific IP Address - Video [Last Updated On: November 12th, 2014] [Originally Added On: November 12th, 2014]
- A Computer Science Professor Found A Way To Identify Most 'Anonymous' Tor Users [Last Updated On: November 19th, 2014] [Originally Added On: November 19th, 2014]
- Tor Browser-in Yuklenmesi ve qurulmasi. - Video [Last Updated On: November 26th, 2014] [Originally Added On: November 26th, 2014]
- | | install tor browser on ubuntu 14 04 - Video [Last Updated On: November 29th, 2014] [Originally Added On: November 29th, 2014]
- Tor Browser 4.5-alpha-1 is released | The Tor Blog [Last Updated On: November 29th, 2014] [Originally Added On: November 29th, 2014]
- Como instalar o Tor Browser- Navegador da Deep Web/Annimo - Video [Last Updated On: December 5th, 2014] [Originally Added On: December 5th, 2014]
- [ExpertProf - THT]Tor Browser Kurulumu Ve Onion'a Girilmesi - Video [Last Updated On: December 5th, 2014] [Originally Added On: December 5th, 2014]