T1041

Exfiltration Over C2 Channel

discovered 2025-08-12

Stolen credentials and host data exfiltrated to a Tor hidden-service C2 (/api/agent), with temp.sh as a Tor-tunneled fallback.

View on MITRE ATT&CK

Seen in packages

Campaigns