Cold$eal
Aliases: ColdSeal
- Malware type
- cryptominer
- Profile updated
- 2026-07-07 14:54:02
Context
Cold$eal is a packer for encrypting (sealing) malware. It contains some AV-evasion techniques as well as some sandbox-detection. It was developed by $@dok (aka Sadok aka Coldseal). It was available as a cryptor service under the url coldseal.us and was later sold as a toolkit consisting of the cryptor and a custom made cryptostub including a FuD garantee backed by free update to the cryptostub. The payload was encrypted using RC4 and added to the cryptostub as a resource. The encryption key itself was stored inside the resource as well. Upon start the cryptostub would extract the key, decrypt the payload and perform a selfinjection using the now decrypted payload. Note: The packed sample provided contains some harmless payload, while the unpacked sample is the bare cryptostub without a payload.
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Coldseal (report)
- web.archive.org — Return Of Fake Ups Cannot Deliver Malspam With An Updated Nemucod Ransomware And Kovter Payload (report)
- xylibox.com — Coldeal Situation Is Under Control (report)
- xylibox.com — Cracking Coldeal 541 Fwb (report)
- youtube.com — Watch (report)
- web.archive.org — Fake Cdc Flu Pandemic Warning Delivers Gandcrab 5 2 Ransomware (report)