SubZero is referenced as a ransomware threat actor associated with the use of Component Object Model (COM) abuse for Windows User Account Control bypass. High-confidence reporting in the available material is limited to this technique association, and does not establish broader attribution, victimology, operating model, malware family details, or geographic origin. Based on the supported facts, SubZero has been observed using defense-evasion and post-compromise tradecraft involving elevated COM manipulation to facilitate execution with reduced user prompts. No additional aliases, sub-groups, targeting patterns, or motivations are currently available from the supplied information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.