logo

Prolific Russian hacking unit using custom backdoor for the first time

ID: 4ce04861-15b6-5442-ad6d-45b6598cf472

STIX ID: report--4ce04861-15b6-5442-ad6d-45b6598cf472

Feed Name: CyberScoop

Threat Score
85/100

Date Published: 2024-01-18

Date Updated: 2026-04-21

Author: AJ Vicens

...
...

Google’s Threat Analysis Group reports that the Russian-linked APT known as Cold River (also tracked as Callisto/Star Blizzard/UNC4057) has added a custom backdoor named SPICA to its toolkit. SPICA provides command execution, file upload/download, and system/file reconnaissance and has been used in highly targeted operations since at least September; the report situates this capability within Cold River’s ongoing espionage campaigns against NGOs, military and research targets and notes links to the FSB and prior legal actions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.