Coldzer0 is a malware author associated with the Coldroot remote access trojan targeting macOS. The actor has been publicly linked to development and attempted commercialization of Coldroot, a feature-complete RAT that masquerades as legitimate Apple-related software and relies on social engineering to induce execution and credential entry. Reported activity also includes compromise of online forums and theft of large volumes of user information, indicating both malware development and intrusion activity. Coldroot is a cross-platform RAT written in Pascal with functionality focused on post-compromise control of infected systems. Its capabilities include host reconnaissance, file and directory management, process execution and termination, remote desktop access, keylogging, and exfiltration of system and user information. The malware establishes persistence on macOS through launch daemon installation and attempts to obtain elevated access by prompting for user credentials. It also sought to abuse macOS accessibility and privacy mechanisms to enable surveillance functions such as keylogging, although newer macOS protections reduce the effectiveness of some of these techniques. Operationally, Coldzer0 has been associated with credential harvesting through fake authentication prompts, persistence mechanisms, remote command execution, and data theft from compromised hosts. The actor has also been tied to theft of user data from breached web forums. Available information supports characterization of Coldzer0 primarily as a financially motivated criminal actor involved in malware development, unauthorized access, surveillance-oriented post-exploitation, and information theft rather than a nation-state operator.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the named actor behind hacks of vBulletin and Foxit Software forums resulting in theft of hundreds of thousands of users' information.
Coldzer0 is the author and operator of Coldroot, a cross-platform remote access trojan (RAT) targeting macOS (and other platforms). Coldroot is a feature-complete RAT capable of keylogging, remote desktop, file management, process control, and persistence. It is distributed as a fake Apple audio driver and attempts to masquerade as a legitimate application. The malware is designed to evade detection and was undetected by AV engines at the time of analysis. Coldroot was offered for sale and its source code and demo videos were publicly available.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.