logo

Google links new LostKeys data theft malware to Russian cyberspies

ID: 5c698cce-b4bf-59ba-b11a-2671b82a8ea2

STIX ID: report--5c698cce-b4bf-59ba-b11a-2671b82a8ea2

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-05-08

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Since early 2024, the Russian state-backed ColdRiver group has deployed a new VBS data-stealer called LostKeys in highly selective ClickFix social‑engineering attacks that trick targets into running PowerShell scripts; the malware exfiltrates files, system information, and running processes from Western governments, journalists, think tanks, NGOs and other high‑value targets, prompting alerts from Google Threat Intelligence, Five Eyes agencies, and U.S. sanctions and indictments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.