s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-osx.coldroot_rat

📛 Threat Title

Malware family: Coldroot RAT

Category: Coldroot RAT First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `osx.coldroot_rat`. Printable name: Coldroot RAT.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:blog.sucuri.net

    Learn what a Remote Access Trojan is, how RATs work, the risks they pose, and how to protect against infections. We cover the basics, examine real incidents where websites spread RAT infections, and provide practical advice for securing your devices against a RAT .

  • web:cybersecuritynews.com

    Two sophisticated Linux rootkits are posing increasingly serious threats to network security by exploiting eBPF technology to hide their presence from traditional detection systems. BPFDoor and Symbiote, both originating from 2021, represent a dangerous class of malware that combines advanced kernel-level access with powerful evasion capabilities.

  • web:github.com

    For educational purposes only, exhaustive samples of 500+ classic/modern trojan builders including screenshots. - Cryakl/Ultimate- RAT -Collection

  • web:macos.checkpoint.com

    Coldroot was first published as an open source RAT for macOS on Github on 2016, but no real malware was discovered until 2018. The malware is weaponized with a wide range of commands such as:- File/Folders control (move, reanme, delete) - Remote Desktop - Download, upload and executes files - Process control (list, execute, kill) - Taking screen shots - Gain accessibility rights by ...

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the Coldroot RAT malware family including references, samples and yara signatures.

  • web:research.splunk.com

    This Analytic Story addresses the ColdRoot remote access trojan ( RAT ), which was uploaded to Github in 2016, but was still escaping detection by the first quarter of 2018, when a new, more feature-rich variant was discovered masquerading as an Apple audio driver.

  • web:serviceteamit.com

    Year-Old Coldroot RAT Targets MacOS, Still Evades Detection Researchers are warning users about the Coldroot remote access Trojan that is going undetected by AV engines and targets MacOS computers. The RAT is cross-platform and capable of planting a keylogger on MacOS systems prior to the OS High Sierra and is designed to steal banking credentials.

  • web:undercodetesting.com

    Introduction Remote Access Trojans ( RATs ) are a growing cybersecurity threat, enabling attackers to gain unauthorized control over victims' devices, including screen capture, camera access, and credential theft. This article explores RAT detection techniques, mitigation strategies, and the evolving threat landscape. Learning Objectives Identify common RAT behaviors and indicators of ...

  • web:www.fortinet.com

    FortiGuard Labs discovered new Symbiote and BPFDoor variants exploiting eBPF filters to enhance stealth through IPv6 support, UDP traffic, and dynamic port hopping for covert C2 communication.

  • web:www.researchgate.net

    Prevention and detection of eBPF-based malware is also explored, with the goal of providing organizations or legitimate users of eBPF techniques to harden their systems against eBPF-based malware ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.