Russian cyber snoops linked to massive credential-stealing campaign
ID: 5e824e79-0319-5e4e-a141-740c9b4786a5
STIX ID: report--5e824e79-0319-5e4e-a141-740c9b4786a5
Feed Name: The Register (Security)
Citizen Lab attributes a multi-year Russian FSB-linked phishing campaign, dubbed "River of Phish," to the COLDRIVER group and a second actor COLDWASTREL; the campaign (since 2022) uses spear-phishing PDFs, browser fingerprinting and phishing pages to steal credentials and 2FA tokens from exiled Russian opposition, NGOs, media, think tanks, defense-industry and government personnel across the US and Europe — no malware was observed, but credential theft poses significant personal and national security risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
