Josh Pitts of Leviathan Security Group has identified a Tor exit node that was actively adding malware to binary files dynamically. He ran across the misbehaving Tor exit node while performing some research on download servers that might be patching binaries during download through a man-in-the middle attack. An article about this can also be found at Threat Post.
(Score: 2) by urza9814 on Thursday October 30 2014, @06:30PM
Yup. My phone does this. So any apps that are updated are being updated through Tor. I actually did try limiting Tor to specific applications, but I found that didn't work very well, a lot of apps would claim they had no connection at all. But if you do transparent proxying of ALL traffic, they work perfectly.