
Gozi Banking Trojan Routes C2 Through Trio of Tor Onion Addresses
A Gozi campaign tracked as CTXv7povuldk2 is cycling bot check-ins through three DGA-generated Tor v3 hidden-service addresses, with detection scores dropping from 12/91 to zero across the rotation. An active PHP routing panel on the primary domain and a mapped data-destruction capability signal an operation built for dwell-time, not just credential theft.
Three algorithmically generated Tor v3 hidden-service addresses — each a 56-character base32 string indistinguishable from random noise — are currently routing bot check-ins for an active Gozi banking-trojan campaign tracked by CTX Team as CTXv7povuldk2. The addresses were not registered through any conventional registrar, carry no TLS certificates that could be fingerprinted, and leave no DNS footprint that a sinkhole could intercept.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read