← Back to Pulse Feed
PULSE DETAIL
Torg Grabber has emerged as a sophisticated and evolving credential stealer that began its development targeting victims via the Telegram Bot API, then transitioned to a raw TCP protocol and now employs a production-grade REST API. This malware is indicative of a Malware-as-a-Service (MaaS) model, supported by a wide-ranging criminal infrastructure. Torg Grabber showcases notable advancements in its three-month developmental timeline, during which it presented a rapid evolution from simple Telegram file uploads to a complex exfiltration mechanism using encrypted HTTPS communications.
MITRE ATT&CK & Malware Families
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| IPv4 | 190.92.174.248 | CC=US ASN=AS1239 sprint | 2026-03-29 | |
| IPv4 | 84.200.125.231 | CC=DE ASN=AS44066 accelerated it services & consulting gmbh | 2026-03-29 | |
| URL | http://gogenbydet.cc/findyour-dreams.com | — | 2026-03-29 | |
| URL | http://j0o.pw/core2 | — | 2026-03-29 | |
| URL | http://playbergs.info/50elk.com | — | 2026-03-29 | |
| URL | http://re3.pw/res3.php | — | 2026-03-29 | |
| URL | http://re3.pw/res6.php | — | 2026-03-29 | |
| URL | http://t4e.pw/re3.pw | — | 2026-03-29 | |
| URL | http://t4e.pw/res1.php | — | 2026-03-29 | |
| URL | http://t4e.pw/res2.php | — | 2026-03-29 | |
| URL | http://t4e.pw/res4.php | — | 2026-03-29 | |
| URL | http://t4e.pw/res5.php | — | 2026-03-29 | |
| domain | 50elk.com | — | 2026-03-29 | |
| domain | attackzombie.com | — | 2026-03-29 | |
| domain | avanpost-fi.digital | — | 2026-03-29 | |
| domain | bbcplay.top | — | 2026-03-29 | |
| domain | evasivestars.com | — | 2026-03-29 | |
| domain | findyour-dreams.com | — | 2026-03-29 | |
| domain | gogenbydet.cc | — | 2026-03-29 | |
| domain | new-app-techno.com | — | 2026-03-29 | |
| domain | playbergs.info | — | 2026-03-29 | |
| domain | potshilpo.shop | — | 2026-03-29 | |
| domain | quick-neo.com | — | 2026-03-29 | |
| domain | safeguss.com | — | 2026-03-29 | |
| domain | si-dodgei.digital | — | 2026-03-29 | |
| domain | sinixproduction.com | — | 2026-03-29 | |
| domain | startbuldingship.com | — | 2026-03-29 | |
| domain | tara.net.bd | — | 2026-03-29 | |
| domain | technologytorg.com | — | 2026-03-29 | |
| domain | wulingyuanparkzone.com | — | 2026-03-29 | |
| hostname | bk.tara.net.bd | — | 2026-03-29 | |
| hostname | raketa.tara.net.bd | — | 2026-03-29 |