CryptoBandits Malware Doubles as a Backdoor, Abuses Tor
2026-06-19T13:24:07Z•6921f58c0885987382c1505db88cd35d1767ca037691313cd611084c5aab8768
CISACVE-2026-20253FortiBleedFortinetKlueREDCapSOCKS5SalesforceSocGholishSplunkTorUNC6508backdoorbotnet-takedowncredential-theftdata-exfiltrationdata-theftexploitmalwarepatchingremote-code-executionsupply-chainvulnerability
What happened
Multiple high-risk incidents reported: CryptoBandits is a new malware family that also functions as a backdoor, abuses Tor and a local SOCKS5 proxy to route stolen data and enable remote code execution. A large-scale credential theft campaign dubbed “FortiBleed” compromised roughly 86,000 internet-accessible Fortinet firewalls and VPNs. A Klue supply-chain compromise led to exfiltration of customer Salesforce data (including Huntress and Recorded Future). Splunk Enterprise is being actively exploited for unauthenticated remote code execution via CVE-2026-20253, prompting an urgent CISA three‑‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 6921f58c0885987382c1505db88cd35d1767ca037691313cd611084c5aab8768
- Enrichment time
- 2026-06-19T13:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.