Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Security Privacy

A Mysterious Threat Actor is Running Hundreds of Malicious Tor Relays (therecord.media) 20

Since at least 2017, a mysterious threat actor has run thousands of malicious servers in entry, middle, and exit positions of the Tor network in what a security researcher has described as an attempt to deanonymize Tor users. The Record: Tracked as KAX17, the threat actor ran at its peak more than 900 malicious servers part of the Tor network, which typically tends to hover around a daily total of up to 9,000-10,000. Some of these servers work as entry points (guards), others as middle relays, and others as exit points from the Tor network.

Their role is to encrypt and anonymize user traffic as it enters and leaves the Tor network, creating a giant mesh of proxy servers that bounce connections between each other and provide the much-needed privacy that Tor users come for. Servers added to the Tor network typically must have contact information included in their setup, such as an email address, so Tor network administrators and law enforcement can contact server operators in the case of a misconfiguration or file an abuse report. However, despite this rule, servers with no contact information are often added to the Tor network, which is not strictly policed, mainly to ensure there's always a sufficiently large number of nodes to bounce and hide user traffic.

This discussion has been archived. No new comments can be posted.

A Mysterious Threat Actor is Running Hundreds of Malicious Tor Relays

Comments Filter:

"It's the best thing since professional golfers on 'ludes." -- Rick Obidiah

Working...