Analysis of Attack Activities Using SSH+TOR Tunnels to Achieve Covert Persistence
Reported 29 Apr 2026 by otx · Severity: medium
APT-C-13 (Sandworm), also known as FROZENBARENTS, is a state-sponsored advanced persistent threat group conducting global cyber espionage operations. The organization recently deployed malicious campaigns using nested SSH and TOR tunnel infrastructure to establish covert remote a