Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe
ID: fe63ca13-a2ac-5f7f-90c4-1b8e4fd26cbf
STIX ID: report--fe63ca13-a2ac-5f7f-90c4-1b8e4fd26cbf
Feed Name: The Citizen Lab
Threat Score
This Citizen Lab report documents a sophisticated, targeted spear‑phishing campaign (“River of Phish”) attributed to COLDRIVER (linked to the Russian FSB) and a separate actor named COLDWASTREL; attackers use highly personalized email lures and fake “encrypted” PDFs that redirect to credential‑harvesting phishing pages, with multiple IoCs, PDF metadata patterns, and mitigation recommendations provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
