Cult of the Dead Cow (cDc) is a hacker and hacktivist group founded in 1984 in Lubbock, Texas, and is described in the provided content as the oldest active group in the hacker underground. By the mid-1990s, the group is described as having become explicitly political, leveraging technology to advance human rights and protect the free flow of information. The term "hacktivism" is attributed in the content to Omega of cDc in 1996. The group has been associated with support for dissidents and anti-censorship efforts, including work through its Hacktivismo division and collaboration with the Hong Kong Blondes; the content states cDc later announced it would no longer work with the Hong Kong Blondes after helping them develop hacking capability. The content also notes cDc was part of an international coalition of hackers that in 1999 condemned Legion of the Underground’s declaration of "war" against governments and argued against damaging national information infrastructure. The group is widely known in the provided content for releasing Back Orifice in 1998, a Windows remote administration tool/backdoor trojan that enabled remote control of infected systems, and Back Orifice 2000. The content also attributes to cDc and its Hacktivismo division the release of ScatterChat, an open-source secure instant messaging client for activists and political dissidents that used Tor and end-to-end encryption, as well as the later Veilid privacy-focused end-to-end encrypted protocol and application framework. The content further references cDc’s long-running public presence, conference appearances, and involvement in the conflict known as "Scientology versus the Internet." Known aliases and related names directly mentioned in the content include cDc and CDC; Hacktivismo is identified as a division/sub-group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly developed the Back Orifice remote administration tool discussed in the article.
Created malware in 1998 to exploit weaknesses in Windows and enable remote control of infected devices via a trojan-installed backdoor.
Hacktivist group announcing and developing Veilid, an open-source, peer-to-peer, mobile-first encrypted application framework and secure messaging platform focused on privacy and resisting data monetization.
Referenced historically as the group associated with coining '31337'/'Eleet'; no active malicious campaign, malware use, targeting, or operations are described in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.