Microsoft Defender will finally stop claiming Tor is malware

Illustration about 'Darknet', logo of the Tor Browser, which provides access to the Darknet. Binary codes are shown in the background
(Image credit: Photo by Florian Gaertner/Photothek via Getty Images)

Tor has confirmed that Microsoft Defender will no longer wrongly flag the alternative browser as malware after a battle with Microsoft to get the story straight.

The problem stems from TorBrowser 12.5.6, which contains an executable file that Defender deemed unsafe, but a Tor spokesperson said that the file was actually unchanged byte-for-byte compared with version 12.5.5.

Affected users were having the tor.exe file flagged as a trojan (“Win32/Malgent!MTB”) and were unable to use the software.

Microsoft will let you use the Tor browser again

In the meantime, some users were reporting success in reinstalling the previous build, which was not seemingly triggering Windows Defender’s trojan response.

Compared with Tor version 12.5.5, build 12.5.6 added just a couple of security tweaks including backporting security fixes from Firefox 115.3.1 to 102.15.1.

It took Tor contacting Microsoft to get it working correctly again. By sharing the .exe file with Redmond, Tor was told:

“At this time, the submitted files do not meet our criteria for malware or potentially unwanted applications. The detection has been removed.”

The update reads: “If your TorBrowser stopped working during this weekend, make sure your Windows Defender is up to date, and either unquarantine tor.exe, or reinstall TorBrowser by downloading it from [the] Tor Project website.”

The latest signature database (1.397.1910.0) is no longer considering the tor.exe file to be a problem.

A Microsoft spokesperson told TechRadar Pro in an email:

"Because the Tor.exe software is used for both illegitimate and legitimate use, it’s not trivial to determine whether its presence in any particular situation is safe or unsafe. Detections where Tor.exe is concerned usually covers the malicious behaviors or other indicators of compromise surrounding usage of the application (tor.exe) and not on Tor.exe itself. In this case, it was determined as a false positive detection and we have released a security intelligence update to fix the issue."

More from TechRadar Pro

Craig Hale

With several years’ experience freelancing in tech and automotive circles, Craig’s specific interests lie in technology that is designed to better our lives, including AI and ML, productivity aids, and smart fitness. He is also passionate about cars and the decarbonisation of personal transportation. As an avid bargain-hunter, you can be sure that any deal Craig finds is top value!

Read more
Phone scammer
Microsoft thinks it could stop this dangerous scam forever
Woman using a Windows computer with Microsoft Edge
Don’t panic – Microsoft’s Edge browser isn’t about to subject you to a flood of unblocked adverts (not yet, anyway)
Home internet connection. A wlan router on desk with notebook in background.
Cloudflare admits security tool is blocking some challenger browsers
Docker Hub Office
False malware alert is leading Docker Desktop to be blocked on Apple Macs
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
A computer being guarded by cybersecurity.
Worrying Windows security issue patched by 7-Zip, so patch now
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news