Prolific Russian hacking unit using custom backdoor for the first time
ID: 4ce04861-15b6-5442-ad6d-45b6598cf472
STIX ID: report--4ce04861-15b6-5442-ad6d-45b6598cf472
Feed Name: CyberScoop
Google’s Threat Analysis Group reports that the Russian-linked APT known as Cold River (also tracked as Callisto/Star Blizzard/UNC4057) has added a custom backdoor named SPICA to its toolkit. SPICA provides command execution, file upload/download, and system/file reconnaissance and has been used in highly targeted operations since at least September; the report situates this capability within Cold River’s ongoing espionage campaigns against NGOs, military and research targets and notes links to the FSB and prior legal actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
