RooTroy is a BlueNoroff-linked malware family used in the SnatchCrypto operation, specifically in the GhostCall and GhostHire campaigns targeting the Web3 and blockchain ecosystem. It is associated with BlueNoroff, also tracked as Sapphire Sleet, APT38, Stardust Chollima, TA444, and Alluring Pisces. Victims described in the reporting include blockchain developers, executives, managers, tech companies, and venture capital firms, with observed activity across multiple countries and on both macOS and Windows.
The malware is described as a Go-based backdoor/downloader family. On macOS, RooTroy.macOS is identified as a final payload written in Go. Reporting states that RooTroy on macOS is deployed through a chain involving a Go installer, a Nimcore loader, and GillyInjector, which injects the Go backdoor. Its documented capabilities include collecting device information, enumerating running processes, monitoring processes and volumes, reading a payload from a specific file, downloading additional ZIP payloads, and downloading and executing additional malware, including RealTimeTroy. RooTroy also deployed additional files named keyboardd and airmond, identified respectively as a keylogger and an infostealer.
On Windows, RooTroy.Windows is described as the first non-scripted malware installed on an infected host and as a simple downloader written in Go, similar to malware used in the GhostCall campaign. It was observed in GhostHire infections alongside RealTimeTroy, a Go-based CosmicDoor variant, and a Rust-based Bof loader. Reporting states that RooTroy.Windows operated through a service named NetCheckSvc, stored configuration in C:\Windows\system32\smss.dat, and used RC4-encrypted payload delivery and process injection.
Infection vectors tied to RooTroy are the broader GhostCall and GhostHire social-engineering chains. GhostCall used fake Zoom- or Microsoft Teams-themed meeting pages delivered via Telegram and phishing domains; on macOS this led to malicious AppleScript and DownTroy, which then deployed payloads including RooTroy. GhostHire used fake recruiter personas, Telegram bots, GitHub repositories, and malicious coding assessment projects or dependencies to deliver DownTroy and subsequent payloads, including RooTroy on Windows. The content also notes RooTroy as part of implant chains that performed credential theft, keylogging, persistence, and follow-on malware delivery.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The final payload is identified as RooTroy.macOS, written in Go. ... RooTroy.Windows is the first non-scripted malware installed on an infected host. It is a simple downloader written in Go, same to the malware used in the GhostCall campaign.
RooTroy ... injects a Go backdoor called RooTroy (aka Root Troy V4) to collect device information, enumerate running processes, read payload from a specific file, and download additional malware (counting RealTimeTroy) and execute them.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
Later, a persistence mechanism is implemented through macOS Launch Daemon plists... The installer completes the persistence setup by using legitimate launchctl commands to activate the persistence mechanism.
The malware samples were found written in multiple programming languages, including Go, Rust, Nim, and AppleScript, reflecting an added technical layer in the group’s operations.
RooTroy collects and lists all mounted volumes and running processes... SneakMain.macOS constructs a JSON object containing this information, along with additional fields such as... process list... SysPhon... Process list ps aux.
all three DownTroy strains collect comprehensive system information including OS details, domain name, host name, username, proxy settings, and VM detection alongside process lists... SysPhon... conduct system reconnaissance by executing a series of commands.
Once inside the target environment, the malware seeks out crypto wallet data, SSH keys, and project credentials–anything that could enable financial theft or lateral movement within corporate infrastructure.
The page reports back to their backend infrastructure through a series of automatically triggered HTTP GET requests... RooTroy sends the collected information to the C2 server via a POST request to /update endpoint... additional files are retrieved with GET.
DownTroy would download ZIP files that contain various individual infection chains from the actor’s centralized file hosting server... When both the url and auth fields are present, RooTroy connects to the URL... to retrieve additional files.
The main feature of CosmicDoor is that it communicates with the C2 server using the WSS protocol, and it provides remote control functionality such as receiving and executing commands... SneakMain... receives additional AppleScript commands and uses the osascript -e command to execute them.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A payload used on macOS and Windows in the described campaigns, deployed as part of a multi-stage toolset.
Rootroy is an implant used in BlueNoroff's GhostCall campaign, focused on establishing persistence within compromised systems as part of a multi-stage malware chain.
Go-based backdoor delivered via loader/injection chain; performs host discovery (device info, process enumeration), reads payloads from a file, and downloads/executes additional malware including RealTimeTroy.
A Go-based cross-platform malware family used as a downloader/backdoor. On macOS it executes commands, monitors volumes and processes, downloads additional ZIP payloads, and deploys secondary tools including a keylogger and infostealer. On Windows it decrypts configuration, communicates with C2 in JSON, supports payload injection and self-update, and loads further malware such as RealTimeTroy.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.