Re: [tor-talk] Mirai Botnet Relocates To Onions

On 12/17/2016 10:11 PM, grarpamp wrote:
> https://www.bleepingcomputer.com/news/security/security-firms-almost-brought-down-massive-mirai-botnet/


> Currently, to avoid further takedown attempts from similar security
> firms, BestBuy has started moving the botnet's command and control
> servers to Tor. "It's all good now. We don't need to pay thousands to
> ISPs and hosting. All we need is one strong server," the hacker said.
> "Try to shut down .onion 'domains' over Tor," he boasted, knowing that
> nobody can.

OK. However, it's not hard to scan for connections to Tor servers. And
you don't expect them for random devices. But maybe Mirai is setup to
use bridges.
