CryptoBandits Malware Doubles as a Backdoor, Abuses Tor

2026-06-19T13:24:07Z6921f58c0885987382c1505db88cd35d1767ca037691313cd611084c5aab8768
CISACVE-2026-20253FortiBleedFortinetKlueREDCapSOCKS5SalesforceSocGholishSplunkTorUNC6508backdoorbotnet-takedowncredential-theftdata-exfiltrationdata-theftexploitmalwarepatchingremote-code-executionsupply-chainvulnerability

What happened

Multiple high-risk incidents reported: CryptoBandits is a new malware family that also functions as a backdoor, abuses Tor and a local SOCKS5 proxy to route stolen data and enable remote code execution. A large-scale credential theft campaign dubbed “FortiBleed” compromised roughly 86,000 internet-accessible Fortinet firewalls and VPNs. A Klue supply-chain compromise led to exfiltration of customer Salesforce data (including Huntress and Recorded Future). Splunk Enterprise is being actively exploited for unauthenticated remote code execution via CVE-2026-20253, prompting an urgent CISA three‑‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
6921f58c0885987382c1505db88cd35d1767ca037691313cd611084c5aab8768
Enrichment time
2026-06-19T13:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.