Legion of Doom (LOD) was a prominent early U.S. hacker group active in the bulletin board system era and associated with influential members including Lord Digital and Dead Lord. In the context of Apple II malware activity, LOD-linked aliases were connected to the CyberAIDS and Festering Hate ProDOS virus family through the pseudonyms Cereal Killer and Rancid Grapefruit. Those malware variants were among the earliest known Apple II ProDOS viruses and were notable for destructive behavior: infecting system files across disks and memory and ultimately destroying data when no clean files remained. The malware was reportedly propagated through pirate software distribution channels and later reached broader Apple II users, including via shareware ecosystems. Festering Hate, the final known 1988 iteration of the CyberAIDS code base, included taunting messages and attribution to the Kool/Rad Alliance. LOD members Lord Digital and Dead Lord were later associated with launching MindVox. The group is historically significant as part of the formative North American underground hacking scene rather than as a modern financially motivated intrusion set.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named hacking group whose members Lord Digital and Dead Lord are discussed in connection with the pseudonyms tied to the CyberAIDS/Festering Hate activity.
Referenced as the broader hacker group whose members Lord Digital and Dead Lord were associated with the pseudonyms tied to the CyberAIDS/Festering Hate activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.