logo

Russian cyber snoops linked to massive credential-stealing campaign

ID: 5e824e79-0319-5e4e-a141-740c9b4786a5

STIX ID: report--5e824e79-0319-5e4e-a141-740c9b4786a5

Feed Name: The Register (Security)

Threat Score
85/100

Date Published: 2024-08-14

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Citizen Lab attributes a multi-year Russian FSB-linked phishing campaign, dubbed "River of Phish," to the COLDRIVER group and a second actor COLDWASTREL; the campaign (since 2022) uses spear-phishing PDFs, browser fingerprinting and phishing pages to steal credentials and 2FA tokens from exiled Russian opposition, NGOs, media, think tanks, defense-industry and government personnel across the US and Europe — no malware was observed, but credential theft poses significant personal and national security risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.