logo

Russian State-Sponsored Threat Actor Targets High Profile Individuals in Phishing Campaign

ID: ee5fd4ee-b86d-5c03-9a69-57a3cc0b3917

STIX ID: report--ee5fd4ee-b86d-5c03-9a69-57a3cc0b3917

Feed Name: KnowBe4 Blog

Threat Score
85/100

Date Published: 2024-01-22

Date Updated: 2026-04-28

Author: Stu Sjouwerman

...
...

COLDRIVER, a Russian state-linked actor, is conducting targeted credential-phishing campaigns against NATO countries, Ukraine, NGOs, and high-profile individuals. The actor uses impersonation accounts to share benign-looking PDFs; when recipients report they cannot read the document, COLDRIVER supplies a cloud-hosted “decryption” utility that is actually the SPICA Rust backdoor, enabling shell command execution, browser cookie theft, file transfer, and document exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.