MILDFROST is a passive Java JAR backdoor used by the financially motivated BREEZE COMET threat actor. It provides redundant access to compromised environments through covert DNS-tunneling command-and-control, serving as a fallback channel when other communications are unavailable or detected. Its command set supports shell-command execution and file-transfer operations. BREEZE COMET has used MILDFROST in intrusions targeting Brazilian financial services, payment processors, retailers, exchanges, fintech companies, and banking-software providers, particularly organizations connected to Brazilian payment and banking systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
MILDFROST, a passive Java JAR backdoor that's used to establish covert DNS tunnels.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Passive Java JAR backdoor used to establish covert DNS tunnels.
Passive Java backdoor using covert DNS tunnels, including DnsCommandBeacon.class, as fallback command-and-control.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.