Security researchers from Kaspersky who monitor the activities of cybercriminals on the Darknet, and particularly on the Tor network, have discovered that the number of activities taking place through the anonymous network is increasing.
According to Kaspersky Lab researcher Sergey Lozhkin, there are currently around 900 hidden Tor services with 5,500 nodes and 1,000 exit nodes.

Cybercriminals are attracted to the Tor network for a number of reasons. It allows them to create anonymous underground forums and marketplaces, and they can use it to create command and control (C&C) infrastructure for malware that will be difficult to disrupt.
Examples of malware that use the Tor network for C&C communications are ZeuS, Chewbacca, and the even more recent Backdoor.AndroidOS.Torec.a (an Android Trojan).
Using Tor for malware has its advantages and disadvantages. The fact that Tor-based malware is larger in size and harder to develop makes it rarer, but not non-existent. Lozhkin believes that their number will soon increase.
