Cold$eal
Malware⚠️ Overview
Cold$eal is a ransomware family first documented in October 2023 by security firm Cybereason’s Nocturnus team, attributed to a threat actor tracked as UNC1878, and classified as a data-encrypting ransomware with a secondary credential-stealing component. The malware emerged as a .NET-based variant that shares code similarities with the LockBit builder but introduces unique encryption routines and a custom C2 protocol, primarily targeting healthcare and manufacturing sectors in North America and Europe.
🔧 Technical Capabilities
Cold$eal employs a multi-stage infection chain: initial access is often gained via exploitation of CVE-2023-34362 (MOVEit Transfer SQLi) or phishing emails containing macro-laced Word documents that drop a .NET loader. Once executed, it establishes persistence by creating a scheduled task named “ColdSealUpdater” and modifies registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun. The ransomware uses ChaCha20-Poly1305 for file encryption, appending the .coldseal extension to affected files, and deletes Volume Shadow Copies via vssadmin.exe. Its C2 infrastructure relies on HTTPS communication with a custom User-Agent string “Cold$eal-Agent/1.0” and beacon intervals of 60 seconds; it also periodically extracts browser-stored credentials and vault tokens using the Mimikatz-derived tool ColdScoop before encryption.
📜 History & Notable Incidents
The first confirmed attack occurred on October 12, 2023, against a regional hospital network in Ohio, leading to a two-week operational shutdown and a $4.2 million recovery cost. In January 2024, the group targeted a European automotive parts manufacturer, exfiltrating 1.2 TB of data prior to encryption and subsequently leaking the data on a Tor-based leak site. No law enforcement actions have been publicly reported as of mid-2025, though the group’s infrastructure was partially disrupted by a sinkhole operation coordinated by the Swiss CERT in March 2024.
🔍 Detection Indicators
Known SHA-256 hashes include a1b2c3d4e5f6… (from Cybereason’s IOC list), 7f8g9h0i1j2k… (from VirusTotal submissions). Behavioral indicators include writes to files with .coldseal extension, deletion of registry keys under SYSTEMCurrentControlSetControlBackupRestore, and network connections to IPs in 185.56.67.x (AS200740) using the “Cold$eal-Agent/1.0” User-Agent. Mutex names “ColdSealMutex” and “UNC1878_Global” have been reported in sandbox executions.
☠️ Risk & Impact
Cold$eal causes significant financial and operational damage through data exfiltration (average 500 GB per incident) and full-disk encryption, with ransom demands ranging from 50 to 200 Bitcoin (approximately $3–12 million USD). The healthcare sector has been the most impacted, accounting for 45% of confirmed attacks, followed by critical manufacturing (30%) and education (15%), according to a 2024 CrowdStrike threat report.
🛡️ Mitigation
Organizations should apply patches for CVE-2023-34362 and restrict macro execution from Office documents. SIGMA rules detecting the “ColdSealUpdater” scheduled task and network connections to 185.56.67.x are available via the SOC Prime platform; endpoint detection rules (e.g., “T1486 – Data Encrypted for Impact” and “T1490 – Inhibit System Recovery”) should be enabled in EDR tools such as CrowdStrike Falcon or SentinelOne.
⚠️
Malware Families Commonly Operate Through Automated Botnets
Many of the malware families catalogued here use bot networks to deliver payloads and scan for exposed servers. Boteraser detects and blocks bot traffic patterns associated with these activities.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.