logo

Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe

ID: fe63ca13-a2ac-5f7f-90c4-1b8e4fd26cbf

STIX ID: report--fe63ca13-a2ac-5f7f-90c4-1b8e4fd26cbf

Feed Name: The Citizen Lab

Threat Score
88/100

Date Published: 2024-08-14

Date Updated: 2026-04-19

Author: John Scott-Railton

...
...

This Citizen Lab report documents a sophisticated, targeted spear‑phishing campaign (“River of Phish”) attributed to COLDRIVER (linked to the Russian FSB) and a separate actor named COLDWASTREL; attackers use highly personalized email lures and fake “encrypted” PDFs that redirect to credential‑harvesting phishing pages, with multiple IoCs, PDF metadata patterns, and mitigation recommendations provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.