# Coldroot macOS RAT evades all antivirus engines

Published: 2026-08-02 · Severity: medium
Canonical: https://vorant.io/reports/21e72171-ab7b-5e4c-b749-99d13f57c1a9/coldroot-macos-rat-evades-all-antivirus-engines

> A cross-platform Pascal-written RAT called OSX/Coldroot persists as root, logs keystrokes, and streams desktops while going undetected by every VirusTotal AV engine.

Objective-See researcher Patrick Wardle discovered an undetected macOS sample, disguised as "com.apple.audio.driver.app," that referenced the TCC.db privacy database — a strong indicator of malicious intent since legitimate code has no reason to touch it. Analysis revealed the malware, dubbed OSX/Coldroot, is a UPX-packed, Pascal-compiled cross-platform remote access trojan that masquerades as a document, tricks users into entering credentials via a fake authentication prompt, and uses those credentials via AuthorizationExecuteWithPrivileges to install itself as a root launch daemon for persistent, privileged execution.

Once installed, Coldroot attempts to grant itself macOS Accessibility permissions (successful only on pre-SIP systems) to enable system-wide keylogging via CoreGraphics event taps, logging captured keystrokes to a local file. It also beacons to a hardcoded C2 server, exfiltrating host survey data (OS version, username, architecture) in JSON, and supports a broad RAT command set including file operations, process listing/execution/kill, upload/download, active window enumeration, remote shutdown, and live remote-desktop screen streaming. The malware's protocol and builder were tied to source code and a demo video from an author using the handle "Coldzer0," who advertised the RAT as a commercial cross-platform remote admin tool with a stated 2017 release date.

Though not technically sophisticated, Coldroot was fully undetected by all AV engines on VirusTotal at time of analysis and had no XProtect signature, illustrating a lingering gap in macOS malware detection. The research was published alongside disclosure of a separate, now-patched macOS UI-spoofing vulnerability the author planned to present at SyScan360, but that flaw is not part of the Coldroot analysis itself.

## Mentioned in this report

- Threat actors: Coldzer0
- Malware: OSX/Coldroot

Source reporting: https://objective-see.org/blog/blog_0x2A.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/21e72171-ab7b-5e4c-b749-99d13f57c1a9/coldroot-macos-rat-evades-all-antivirus-engines.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
