Torpig is a Windows-focused botnet and e-banking trojan first developed in 2005, also known as Anserin and Sinowal. It spread through systems compromised by the Mebroot rootkit and other trojan delivery methods, initially via phishing emails and later via drive-by downloads delivered through malicious banner ads exploiting outdated Java, Adobe Reader/Acrobat Reader, Flash Player, and Shockwave Player installations. Installation involved infecting the Master Boot Record and restarting the system.
Its primary purpose was theft of sensitive personal and corporate data, including bank account information, credit and debit card data, email credentials, Windows passwords, FTP credentials, and POP/SMTP account data. Reported capabilities include credential harvesting, rootkit-based evasion of antivirus software, potential full access to infected systems, modification of data on infected hosts, and man-in-the-browser attacks. During active infection, Torpig reportedly uploaded stolen data every 20 minutes.
The malware is described in the content as one of the most advanced crimeware families of its time. By November 2008, it was estimated to have stolen details from about 500,000 online bank accounts and payment cards. In early 2009, researchers from the University of California, Santa Barbara temporarily took control of the botnet for ten days, redirecting traffic from approximately 1.2 million IP addresses and collecting more than 70 GB of stolen data. During that period, they observed login information for 8,310 accounts at 410 institutions and 1,660 unique payment card numbers, with victims in the United States, Italy, Spain, and 40 other countries.
The content also notes ecosystem and infrastructure observations: Spamhaus reported identifying 506 Torpig command-and-control servers in the first year of its BGP feed reporting. No specific threat actor attribution or concrete IOC values beyond aliases and family associations are provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
More sophisticated delivery methods developed since that time use malicious banner ads which take advantage of exploits found in outdated versions of Java, or Adobe Acrobat Reader, Flash Player, Shockwave Player. A type of Drive-by download, this method typically does not require the user to click on the ad.
It is also purportedly capable of modifying data on the computer, and can perform man-in-the-browser attacks.
During the main stage of the infection, the malware will upload information from the computer twenty minutes at a time, including financial data like credit card numbers and credentials for banking accounts, as well as e-mail accounts, Windows passwords, FTP credentials, and POP/SMTP accounts.
The Spamhaus Botnet C&C (BGPCC) is designed to protect networks and their users from botnet traffic. It can be used to block traffic from/to servers on the internet that are operated by cybercriminals and used to control infected computers (bots) or exfiltrate data.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Torpig is referenced as another malware family with a DGA seeded from nondeterministic external data sources.
Referenced as related malware; no details provided in the content.
See also: Torpig
See also: Torpig
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.