TorNet is a previously undocumented backdoor. Reported activity describes it being delivered by means of PureCrypter and, in one observed campaign, executed simultaneously with PureHVNC by a stealthy dual malware loader. That loader was described as cloaked using MurmurHash2. The available content also associates the reporting with a DDoS tag. High-confidence details beyond these points, including specific capabilities, targeted sectors, threat actor attribution, platforms, or indicators of compromise, are not currently available from the provided content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor newly documented in the referenced reporting; delivered via PureCrypter in phishing campaigns.
Referenced as a payload executed by a stealthy dual malware loader; no further functional details provided in the content.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.