Cult of the Dead Cow (cDc) is a long-running U.S. hacker collective founded in 1984 in Lubbock, Texas, and widely regarded as one of the earliest and most influential hacktivist groups. By the mid-1990s, the group had evolved from underground hacker culture into an explicitly political organization focused on human rights, anti-censorship, privacy, and the free flow of information. cDc is closely associated with the term "hacktivism," which was coined by a member of the group in 1996. Known aliases include cDc and Cult of the Dead Cow (CDC). Associated initiatives and sub-groups include Hacktivismo, which pursued anti-censorship and secure communications projects, and the group has also collaborated with the Hong Kong Blondes in support of pro-democracy causes related to China. The group is historically notable for releasing Back Orifice and Back Orifice 2000, remote administration tools for Microsoft Windows that became emblematic of early offensive and dual-use hacker tooling. These tools enabled remote control of compromised systems and are associated with capabilities including persistence, post-exploitation, credential capture through keylogging, and data access. cDc has also released privacy- and rights-oriented software, including ScatterChat through Hacktivismo and, later, the Veilid privacy-focused peer-to-peer communications framework. These projects were positioned to help activists, dissidents, and ordinary users communicate securely and resist surveillance and censorship. cDc has publicly aligned itself with political and civil-liberties causes. It opposed state censorship, supported dissidents and activists, and participated in public debates over the legitimacy of offensive cyber activity. The group declared conflict with the Church of Scientology during the 1990s internet free-speech disputes, and later joined an international coalition condemning attempts by other hacker groups to wage indiscriminate cyber "war" against national infrastructure. Reporting also links cDc and its affiliates to efforts to help the Hong Kong Blondes develop offensive capability for operations against Chinese government entities and organizations associated with poor human-rights practices. Overall, Cult of the Dead Cow is best characterized as a politically motivated hacktivist collective rather than a conventional cybercrime or state-sponsored intrusion set. Its legacy spans both offensive security culture and privacy-enhancing technology, with influence on hacktivism, anti-censorship activism, and the broader history of hacker collectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Allegedly developed the Back Orifice remote administration tool discussed in the article.
Created malware in 1998 to exploit weaknesses in Windows and enable remote control of infected devices via a trojan-installed backdoor.
Hacktivist group announcing and developing Veilid, an open-source, peer-to-peer, mobile-first encrypted application framework and secure messaging platform focused on privacy and resisting data monetization.
Referenced historically as the group associated with coining '31337'/'Eleet'; no active malicious campaign, malware use, targeting, or operations are described in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.