ZeroTrace Team, also referred to as ZeroTrace, is a Turkish-speaking cybercriminal malware developer and operator associated with information-stealing malware. The group is linked to Raven Stealer and also associated with Octalyn Stealer. Its activity centers on developing, branding, promoting, and distributing commodity stealer malware through public code-hosting platforms and Telegram-based channels. Raven Stealer is a Delphi- and C++-based infostealer focused on harvesting sensitive data from Chromium-based browsers and other local applications. It targets stored credentials, cookies, payment data, autofill records, and additional information from cryptocurrency wallets, gaming platforms, VPN clients, and messaging services. The malware uses Telegram bot functionality for exfiltration and appears designed for operational simplicity and broad criminal use. The malware ecosystem attributed to ZeroTrace Team demonstrates multiple defense-evasion and post-compromise capabilities. Raven Stealer uses packing, in-memory decryption, hidden execution, and reflective process hollowing with direct syscalls. It launches browser processes in suspended and headless states, injects a DLL payload into legitimate processes, and performs in-memory techniques to access protected browser data. Stolen data is staged locally, compressed, and exfiltrated via Telegram. ZeroTrace Team’s observed tradecraft indicates a financially motivated infostealer operation rather than a state-directed espionage actor. The group’s known activity is consistent with credential theft, session theft through browser cookie collection, data exfiltration, process injection, persistence of access to stolen accounts, and broader post-exploitation collection from victim endpoints.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
ZeroTrace is a Turkish-speaking threat actor known for developing the Retro-C2 RAT.
Developer/operator group behind Raven Stealer and also linked to Octalyn Stealer, using GitHub and Telegram to distribute stealer builders, publish updates, and enable Telegram-based credential exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.