VLAD was an Australian hacker group active in early malware development and best known for authoring the Windows 95 virus Boza and for attribution to Staog, an early Linux virus. Reporting associates Staog with Quantum of VLAD. The group is linked to low-level malware written in assembly language and to experimentation across multiple operating systems, including Windows 95 and Linux. In the Staog case, the malware used multiple local privilege-escalation flaws to obtain root privileges, remain resident, and infect executed ELF binaries, demonstrating capabilities in privilege escalation, persistence, and post-exploitation on Unix-like systems. Available information supports VLAD as a malware authoring group rather than a ransomware or extortion actor, and there is no high-confidence evidence here of specific geographic targeting, sector targeting, or a dominant strategic motivation beyond malware creation and offensive experimentation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.