KAX17 is a sophisticated threat actor that has been active since at least 2017. They have operated hundreds of malicious servers within the Tor network, primarily as entry and middle points. Their main objective appears to be collecting information on Tor users and mapping their routes within the network. Despite efforts to remove their servers, KAX17 has shown resilience and continues to operate.
Executive Summary
KAX17 is a long-term threat actor active since 2017, exploiting Tor network infrastructure to monitor user traffic and map network routes. Despite repeated takedown efforts, the group maintains hundreds of Tor nodes, suggesting persistence and resilience. Their activities pose risks to Tor users' anonymity and privacy.
Goals & Targeting
KAX17's primary objective appears to be surveillance and mapping of Tor users' activities, likely to compromise anonymity or gather intelligence on individuals using the network for sensitive communications. By targeting Tor infrastructure, the actor can intercept metadata, identify traffic patterns, and potentially deanonymize users. The group shows no preference for specific sectors or countries, focusing instead on the Tor network itself, which indicates a broad interest in digital privacy threats and network reconnaissance.
Enhanced Description
KAX17 has operated extensively within the Tor network, establishing and maintaining hundreds of malicious relays since at least 2017. These nodes function primarily as entry and middle points, enabling the actor to collect metadata on Tor users and reconstruct network traffic patterns. The group's focus on Tor infrastructure indicates an interest in undermining the anonymity Tor provides, potentially for surveillance or intelligence-gathering purposes. Notably, KAX17 has demonstrated persistence, continuing operations despite efforts by the Tor Project and law enforcement to dismantle their infrastructure. This resilience suggests advanced operational capabilities and a clear strategic objective of long-term network monitoring.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
KAX17 has maintained a low operational tempo focused on long-term Tor infrastructure exploitation since 2017. Campaigns involve deploying malicious Tor relays to monitor user traffic and map network routes. The actor's persistence highlights an emphasis on sustained surveillance rather than short-term disruptive goals. Notable operations include repeated reestablishment of Tor nodes after takedowns, suggesting access to resources for rapid redeployment.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in KAX17's activities is medium, based on observable Tor network infrastructure patterns and historical activity logs. However, limited public disclosure of tools, malware samples, or explicit attribution leaves gaps in understanding their full operational scope, affiliations, and ultimate objectives. Further analysis of network traffic and relay node configurations is needed for higher confidence.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics