ColdRoot is a Pascal-based remote access trojan targeting macOS and described in some reporting as cross-platform. Publicly available variants have masqueraded as legitimate Apple software components to induce execution and credential entry. After launch, ColdRoot can establish persistence on macOS through launchd-based mechanisms and attempts to obtain elevated or privacy-sensitive access needed for surveillance functions. On older macOS versions, it has been observed trying to alter accessibility and privacy controls to enable keylogging, although newer platform protections such as System Integrity Protection reduce the effectiveness of some of these techniques.
ColdRoot is a feature-rich RAT that supports remote command execution, process creation and termination, file and directory operations, host reconnaissance, upload and download, and remote desktop-style monitoring through repeated screen capture. It can steal passwords from macOS keychains, capture keystrokes, collect host metadata, and exfiltrate victim information to command-and-control infrastructure. Analyses of the malware also describe plaintext configuration storage and a command loop that processes operator tasking after initial beaconing.
ColdRoot has been associated with macOS-focused intrusion activity and has been referenced alongside APT32 tradecraft in discussions of macOS living-off-the-land abuse. It is notable less for technical sophistication than for breadth of functionality and its demonstration that macOS systems remain viable targets for persistent remote-access malware.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Used in the wild by APT32 and malware families like OSX.Coldroot RAT, it is one of the most versatile LOLBins on macOS.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
This Analytic Story addresses the ColdRoot remote access trojan (RAT)... the new ColdRoot RAT could start and kill processes on the breached system, spawn new remote-desktop sessions, take screen captures and assemble them into a live stream of the victim's desktop, and more.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as a macOS remote access trojan in a list of detections/content items; no further behavior is described in this reference.
A macOS remote access trojan referenced only as the associated analytic story for this removed Splunk investigation.
A macOS remote access trojan (RAT) referenced in a Splunk detection for identifying ColdRoot-related launchd and file events on macOS systems.
A macOS remote access trojan referenced as using osascript for execution or persistence-related activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.