C0d0so, also known as C0d0s0 and Codoso, is a threat actor associated with the Bergard Trojan and a November 2014 watering-hole attack involving the Forbes website. Its documented activity includes compromising a legitimate website to facilitate malware delivery and using Bergard for command-and-control and follow-on payload execution. Bergard uses single-byte XOR encoding to conceal strings, with a distinctive five-byte padding structure. Its command functionality supports system-information collection and payload retrieval and execution. An observed Bergard infection retrieved an encoded PlugX payload concealed within a PNG image. Bergard and related tools exhibit shared implementation characteristics, but those similarities do not establish that all campaigns using them have the same operator. The actor's country of origin, state affiliation, dominant motivation, and geographic or industry targeting are not established.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
83 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the November 2014 Forbes.com watering-hole attack using Bergard. The report investigates potentially related campaigns, including Bassos, whose Rekaf command-and-control infrastructure showed over 2,000 unique infections. Connections to Bassos, mail-news, PGV_PVID, and UID_SID remain tentative: shared malware and code similarities do not establish common attribution, and infrastructure differences suggest multiple groups might use the toolset. Observed activity suggests an organized weekday operation near GMT+8, but does not establish a source country or state sponsor. Malware and techniques listed below include those from potentially associated campaigns, not uniformly confirmed C0d0s0 operations.
Associated with the 2014 Forbes watering hole attack and later campaigns involving the Bergard toolset, including the Bassos campaign. The report discusses possible links between C0d0s0 and PGV_PVID, UID_SID, and mail-news activity, while noting attribution uncertainty and the possibility that the Bergard toolset is shared by multiple groups.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.