logo

Russian hackers evolve malware pushed in "I am not a robot" captchas

ID: a35dd6cb-2fa5-51f0-9bc8-505bb0e75285

STIX ID: report--a35dd6cb-2fa5-51f0-9bc8-505bb0e75285

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-10-21

Date Updated: 2026-07-18

Author: Bill Toulas

...
...

Google TAG reports that Russian FSB-linked Star Blizzard (ColdRiver/UNC4057/Callisto) abandoned LostKeys and rapidly deployed new malware families (NOROBOT, YESROBOT, MAYBEROBOT) in complex ClickFix fake-CAPTCHA delivery chains; the toolset includes a DLL loader, Python and PowerShell backdoors, persistence via registry and scheduled tasks, split-cryptography payloads to hinder analysis, and has been observed in espionage operations targeting Western governments, journalists, think tanks, and NGOs between June and September, with IoCs and YARA rules published to aid detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.