Skip to content

Author

S. Pastrana

1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Jul 2026

Tor Through the Lens of OSINT: Studying the Presence of Exit Nodes in Blocklists

Tor is a darknet known for its double use. On the one hand, it helps to protect privacy and anonymity for users, e.g., for oppressed groups or activists willing to hide their identities. On the other hand, malicious actors profit from the inherent properties of Tor to avoid prosecution. However, the prevalence and characteristics of such misuse are unclear. To fill this gap, this paper presents an analysis of the usage of Tor for malicious purposes. We present a novel measurement that leverages publicly available data from reputable blocklist providers. We deploy an automatic monitoring system to detect the presence of exit nodes possibly involved in malicious activities, including spam delivery, brute-force attacks, and malware distribution. Concretely, we track 55 blocklists daily over a period of two months, covering a wide range of threat types and inclusion policies. Our study identifies the frequency and nature of Tor-related abuses, and also examines re-inclusion patterns to assess persistent or recurring misuse. The findings show that some nodes are repeatedly flagged across multiple lists and categories, suggesting that they are repeatedly abused by adversaries. Overall, by leveraging open-source intelligence, this study offers real-world insights on how Tor is used for malicious activities, highlighting its role within the cyberthreat ecosystem.

Adrián Jiménez-Gamo, S. Pastrana · 0 citations