logo

Google: Russia's ColdRiver APT Unleashes Custom 'Spica' Malware

ID: beefa1b2-096a-59bd-ba24-a4b8130a2382

STIX ID: report--beefa1b2-096a-59bd-ba24-a4b8130a2382

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-01-18

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

ColdRiver (aka Star Blizzard/Blue Charlie/UNC4057) has incorporated a custom Rust-based backdoor called "Spica" into targeted phishing campaigns: attackers send benign-looking PDFs, then trick recipients into running a malicious "decryption" utility that installs Spica, which uses JSON-over-WebSockets C2 and can execute shell commands, steal browser cookies, enumerate and exfiltrate documents. Google TAG researchers observed limited, targeted use against Ukraine, NATO countries, NGOs and academic institutions; the activity is attributed to a Kremlin-aligned actor and presents elevated espionage risk especially around election-related targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.