Kremlin-linked COLDRIVER crooks take pro-democracy NGOs for phishy ride
ID: 3c728ccb-8fd5-5f3f-86b3-919f7de64d30
STIX ID: report--3c728ccb-8fd5-5f3f-86b3-919f7de64d30
Feed Name: The Register (Security)
The Free Russia Foundation and Citizen Lab report that Kremlin-linked COLDRIVER conducted highly personalized spearphishing campaigns against NGOs in Russia and Belarus, using credential-harvesting pages disguised as locked PDF unlock links to steal credentials and exfiltrate email correspondence; Google TAG also reported a custom backdoor called SPICA used by COLDRIVER since 2022, and a separate pro-Russian campaign (COLDWASTREL) has targeted similar organizations for years.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
