QUIETVAULT is a JavaScript-based stealer malware family observed on macOS and Linux that abuses locally installed AI command-line tools and local large language models to improve data discovery and exfiltration. It embeds malicious prompts to direct available LLM tooling to recursively search a victim host for cryptocurrency wallet material and other sensitive configuration data, effectively using the local model as an automated file-triage and collection assistant. Reported behavior includes leveraging local credentials to exfiltrate collected data to remote code-hosting repositories. QUIETVAULT illustrates a broader trend in which threat actors use self-hosted or locally available LLMs to accelerate post-compromise data identification and theft while avoiding the guardrails and visibility associated with commercial AI services. High-confidence reporting supports data theft and post-exploitation use on compromised systems, but does not establish a specific sponsoring state, operator cluster, or broader alias set beyond QUIETVAULT.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.