Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Description

KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primarily as entry and middle points. Their main objective appears to be collecting information on Tor users and mapping their routes within the network. Despite efforts to remove their servers, KAX17 has shown resilience and continues to operate.

AI Analysis

· 1 week ago

Executive Summary

KAX17 is a long-term threat actor active since 2017, exploiting Tor network infrastructure to monitor user traffic and map network routes. Despite repeated takedown efforts, the group maintains hundreds of Tor nodes, suggesting persistence and resilience. Their activities pose risks to Tor users' anonymity and privacy.

Goals & Targeting

KAX17's primary objective appears to be surveillance and mapping of Tor users' activities, likely to compromise anonymity or gather intelligence on individuals using the network for sensitive communications. By targeting Tor infrastructure, the actor can intercept metadata, identify traffic patterns, and potentially deanonymize users. The group shows no preference for specific sectors or countries, focusing instead on the Tor network itself, which indicates a broad interest in digital privacy threats and network reconnaissance.

Enhanced Description

KAX17 has operated extensively within the Tor network, establishing and maintaining hundreds of malicious relays since at least 2017. These nodes function primarily as entry and middle points, enabling the actor to collect metadata on Tor users and reconstruct network traffic patterns. The group's focus on Tor infrastructure indicates an interest in undermining the anonymity Tor provides, potentially for surveillance or intelligence-gathering purposes. Notably, KAX17 has demonstrated persistence, continuing operations despite efforts by the Tor Project and law enforcement to dismantle their infrastructure. This resilience suggests advanced operational capabilities and a clear strategic objective of long-term network monitoring.

Key Capabilities

  • Deployment and maintenance of large-scale Tor relay networks
  • Traffic monitoring and metadata collection via Tor nodes
  • Network mapping and route reconstruction techniques
  • Resilience against infrastructure takedowns
  • Use of custom tools for Tor node management and data exfiltration

MITRE ATT&CK Tactics

Reconnaissance
Command and Control
Data Exfiltration
Defense Evasion

ATT&CK Techniques

T1046 (Data from Network Shared Memory)
T1075 (Data Extraction via Memory Dump)
T1573 (Network sniffing)
T1105 (Custom Command and Control)
T1071.001 (Use of Tor as a Proxy)

Software / Tooling

Tor relay management software
Custom network sniffing tools
Anonymous communication protocols
Infrastructure obfuscation utilities

Campaigns & Victims

KAX17 has maintained a low operational tempo focused on long-term Tor infrastructure exploitation since 2017. Campaigns involve deploying malicious Tor relays to monitor user traffic and map network routes. The actor's persistence highlights an emphasis on sustained surveillance rather than short-term disruptive goals. Notable operations include repeated reestablishment of Tor nodes after takedowns, suggesting access to resources for rapid redeployment.

IOC Patterns

  • Malicious Tor relay IP ranges
  • Unusual SSL certificate configurations on Tor nodes
  • Abnormal traffic patterns from Tor entry/exit relays
  • Suspicious domain registrations linked to Tor infrastructure
  • Unusual relay node configurations (e.g., high bandwidth, low latency)

Recommended Actions

  • Monitor Tor network traffic for anomalies in relay node behavior
  • Implement network traffic analysis tools to detect unexpected data flows
  • Collaborate with the Tor Project to report suspicious relay nodes
  • Enhance firewall rules to block known malicious Tor exit node IP ranges
  • Deploy intrusion detection systems tuned to detect custom C2 protocols

Suggested Tags

APT
Surveillance
Tor Infrastructure Exploitation
Information Collection
Network Monitoring

Confidence Assessment

Confidence in KAX17's activities is medium, based on observable Tor network infrastructure patterns and historical activity logs. However, limited public disclosure of tools, malware samples, or explicit attribution leaves gaps in understanding their full operational scope, affiliations, and ultimate objectives. Further analysis of network traffic and relay node configurations is needed for higher confidence.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Surveillance
Tor Infrastructure Exploitation
Information Collection
Network Monitoring

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.