PULSE NAME
Torg Grabber: Anatomy of a New Credential Stealer
WHITE Meow PetrP.73 2026-03-29 Modified: 2026-03-29
32
IOCs
MEDIUM VOLUME
Torg Grabber has emerged as a sophisticated and evolving credential stealer that began its development targeting victims via the Telegram Bot API, then transitioned to a raw TCP protocol and now employs a production-grade REST API. This malware is indicative of a Malware-as-a-Service (MaaS) model, supported by a wide-ranging criminal infrastructure. Torg Grabber showcases notable advancements in its three-month developmental timeline, during which it presented a rapid evolution from simple Telegram file uploads to a complex exfiltration mechanism using encrypted HTTPS communications.
Indicators of Compromise (32)
All IPv4 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
IPv4 190.92.174.248 CC=US ASN=AS1239 sprint 2026-03-29
IPv4 84.200.125.231 CC=DE ASN=AS44066 accelerated it services & consulting gmbh 2026-03-29
URL http://gogenbydet.cc/findyour-dreams.com 2026-03-29
URL http://j0o.pw/core2 2026-03-29
URL http://playbergs.info/50elk.com 2026-03-29
URL http://re3.pw/res3.php 2026-03-29
URL http://re3.pw/res6.php 2026-03-29
URL http://t4e.pw/re3.pw 2026-03-29
URL http://t4e.pw/res1.php 2026-03-29
URL http://t4e.pw/res2.php 2026-03-29
URL http://t4e.pw/res4.php 2026-03-29
URL http://t4e.pw/res5.php 2026-03-29
domain 50elk.com 2026-03-29
domain attackzombie.com 2026-03-29
domain avanpost-fi.digital 2026-03-29
domain bbcplay.top 2026-03-29
domain evasivestars.com 2026-03-29
domain findyour-dreams.com 2026-03-29
domain gogenbydet.cc 2026-03-29
domain new-app-techno.com 2026-03-29
domain playbergs.info 2026-03-29
domain potshilpo.shop 2026-03-29
domain quick-neo.com 2026-03-29
domain safeguss.com 2026-03-29
domain si-dodgei.digital 2026-03-29
domain sinixproduction.com 2026-03-29
domain startbuldingship.com 2026-03-29
domain tara.net.bd 2026-03-29
domain technologytorg.com 2026-03-29
domain wulingyuanparkzone.com 2026-03-29
hostname bk.tara.net.bd 2026-03-29
hostname raketa.tara.net.bd 2026-03-29