logo

Kremlin-linked COLDRIVER crooks take pro-democracy NGOs for phishy ride

ID: 3c728ccb-8fd5-5f3f-86b3-919f7de64d30

STIX ID: report--3c728ccb-8fd5-5f3f-86b3-919f7de64d30

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2024-09-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

The Free Russia Foundation and Citizen Lab report that Kremlin-linked COLDRIVER conducted highly personalized spearphishing campaigns against NGOs in Russia and Belarus, using credential-harvesting pages disguised as locked PDF unlock links to steal credentials and exfiltrate email correspondence; Google TAG also reported a custom backdoor called SPICA used by COLDRIVER since 2022, and a separate pro-Russian campaign (COLDWASTREL) has targeted similar organizations for years.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.