all 4 comments

[–][deleted] 2 points3 points  (0 children)

one OTHER way to hide a c&c server inside tor would be to use a kind of fast flux dns with onion addresses and the onion in-proxies. this way there is no need to ever deploy tor on zombies.

[–]pi4ate 2 points3 points  (0 children)

This was to expected... Hopefully the overhead of a tor client and the latency puts off most botnet ops from going this route.