Root Troy V4 is a fully featured Go-based macOS backdoor used in a June 2025 intrusion investigated by Huntress and attributed with high confidence to the North Korean threat actor TA444 / BlueNoroff, also tracked as Sapphire Sleet, COPERNICIUM, STARDUST CHOLLIMA, and CageyChameleon. In the reported campaign, the malware was delivered after Telegram-based social engineering and a fake Zoom meeting using deepfake participants convinced a cryptocurrency foundation employee to install a malicious AppleScript disguised as a Zoom extension. Root Troy V4 was one of eight malicious binaries recovered from the victim host and served as a central post-infection controller used to download and execute additional implants.
The malware ran as "remoted" from /Library/WebServer/bin/remoted. It was described as also being called RTV in build artifacts and was reportedly compiled under the user name "dominic." Root Troy V4 stored encrypted configuration, version, and startup files in /Library/Google/Cache/. Its .cfg file was encrypted with RC4 using key 3DD226D0B700F33974F409142DEFB62A8CD172AE5F2EB9BEB7F5750EB1702E2A. Its .version file was encrypted with RC4 using key C4DB903322D17C8CBF1D1DB55124854C0B070D6ECE54162B6A4D06DF24C572DF and contained {"cbot":"1.0.1","rt":"4.0.1"}.
Capabilities directly described in the source material include executing remote AppleScript payloads, running shell commands and detached shell commands, downloading additional malware, and executing those payloads. It also queued command execution until the display was asleep by checking system_profiler SPDisplaysDataType. Root Troy V4 sent host information, boot time, running process data, mounted volumes, and implant versions to a command-and-control endpoint at http://$DOMAIN/update.
The broader intrusion targeted a cryptocurrency organization and reflected BlueNoroff's ongoing focus on cryptocurrency theft and macOS tradecraft. Reported related indicators include SHA256 ad01beb19f5b8c7155ee5415781761d4c7d85a31bb90b618c3f5d9f737f2d320 for the remoted binary.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Root Troy V4 (remoted ): fully featured backdoor, written in Go, and used to download the other payloads as well as run them.
Root Troy V4 (remoted ): fully featured backdoor, written in Go, and used to download the other payloads as well as run them.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Go-based backdoor enabling remote command execution, AppleScript execution, and downloading/executing additional payloads on macOS.
Go-based backdoor for macOS that allows remote code execution, command queuing, and payload delivery, acting as the main controller for post-infection activity.
A Go-based full-featured backdoor that stores encrypted configuration and version data, executes startup scripts, monitors logout events, inventories host data, communicates with C2, and supports remote AppleScript and shell command execution, including deferred execution while the display is asleep.
A backdoor deployed during the BlueNoroff Zoom-themed social engineering attacks to provide attacker access to the compromised host.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.