VORANT. Threat Intelligence Sign in Get the full feed

Coldroot macOS RAT evades all antivirus engines

medium threat

A cross-platform Pascal-written RAT called OSX/Coldroot persists as root, logs keystrokes, and streams desktops while going undetected by every VirusTotal AV engine.

Objective-See researcher Patrick Wardle discovered an undetected macOS sample, disguised as "com.apple.audio.driver.app," that referenced the TCC.db privacy database — a strong indicator of malicious intent since legitimate code has no reason to touch it. Analysis revealed the malware, dubbed OSX/Coldroot, is a UPX-packed, Pascal-compiled cross-platform remote access trojan that masquerades as a document, tricks users into entering credentials via a fake authentication prompt, and uses those credentials via AuthorizationExecuteWithPrivileges to install itself as a root launch daemon for persistent, privileged execution.

Once installed, Coldroot attempts to grant itself macOS Accessibility permissions (successful only on pre-SIP systems) to enable system-wide keylogging via CoreGraphics event taps, logging captured keystrokes to a local file. It also beacons to a hardcoded C2 server, exfiltrating host survey data (OS version, username, architecture) in JSON, and supports a broad RAT command set including file operations, process listing/execution/kill, upload/download, active window enumeration, remote shutdown, and live remote-desktop screen streaming. The malware's protocol and builder were tied to source code and a demo video from an author using the handle "Coldzer0," who advertised the RAT as a commercial cross-platform remote admin tool with a stated 2017 release date.

Though not technically sophisticated, Coldroot was fully undetected by all AV engines on VirusTotal at time of analysis and had no XProtect signature, illustrating a lingering gap in macOS malware detection. The research was published alongside disclosure of a separate, now-patched macOS UI-spoofing vulnerability the author planned to present at SyScan360, but that flaw is not part of the Coldroot analysis itself.

Mentioned in this report

Threat actors Coldzer0
Malware OSX/Coldroot

Source reporting: https://objective-see.org/blog/blog_0x2A.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free