Tor Network C2
Tor is free and open-source software for enabling anonymous communication. Tor directs Internet traffic through a free, worldwide, volunteer overlay network consisting of more than seven thousand relays to conceal a user’s location and usage from anyone conducting network surveillance or traffic analysis.
Using Tor makes it more difficult to trace Internet activity to the user: this includes “visits to Web sites, online posts, instant messages, and other communication forms”. Tor Network can be used by malware to communicate to a C&C server in a hiding node that make it more difficult to detect. Ransomware usually used Tor to host the payment page and even dataleak page.