Malware may have de-anonymized visitors to Tor sites running on the Tor anonymized network. Malware planted on the servers of Freedom Hosting, the “hidden service” hosting provider on Tor. The address was hard-coded into the script the malware injected into browsers. Initial investigations traced the address to defense contractor SAIC, which provides information technology and C4ISR support to the Department of Defense. The geolocation of the IP address corresponds to an SAIC facility in Arlington, Virginia.”]
Source: https://arstechnica.com/tech-policy/2013/08/researchers-say-tor-targeted-malware-phoned-home-to-nsa/

