Operation Zero Disco is a cluster name for activity involving exploitation of Cisco SNMP vulnerabilities to deploy rootkits on compromised systems. Publicly available information in this context is limited and does not support a high-confidence attribution to a specific named threat actor, country of origin, or broader campaign lineage. The activity is notable for combining network-device or infrastructure-focused vulnerability exploitation with stealth-oriented post-compromise tooling in the form of rootkits, indicating an emphasis on persistence and defense evasion after initial access. No corroborated aliases, sub-groups, victimology, or additional operational details are available from the supplied facts at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.