logo

Google TAG: Kremlin cyber spies move into malware with a custom backdoor

ID: 2a93a996-a814-59f2-b12d-4bebb27a685e

STIX ID: report--2a93a996-a814-59f2-b12d-4bebb27a685e

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-01-18

Date Updated: 2026-04-26

Author: Jessica Lyons Hardcastle

...
...

Google TAG attributes a custom Rust backdoor called SPICA to the Kremlin-linked COLDRIVER APT (aka Star Blizzard/UNC4057), reporting targeted spearphishing campaigns beginning as early as November 2022 that used impersonated email accounts and decoy PDFs to deliver a JSON-over-websockets C2 backdoor capable of executing shell commands, stealing browser cookies and documents, and transferring files; TAG published analysis and IoCs including hashes and C2 addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.