Russian hackers evolve malware pushed in "I am not a robot" captchas
ID: a35dd6cb-2fa5-51f0-9bc8-505bb0e75285
STIX ID: report--a35dd6cb-2fa5-51f0-9bc8-505bb0e75285
Feed Name: Bleeping Computer
Google TAG reports that Russian FSB-linked Star Blizzard (ColdRiver/UNC4057/Callisto) abandoned LostKeys and rapidly deployed new malware families (NOROBOT, YESROBOT, MAYBEROBOT) in complex ClickFix fake-CAPTCHA delivery chains; the toolset includes a DLL loader, Python and PowerShell backdoors, persistence via registry and scheduled tasks, split-cryptography payloads to hinder analysis, and has been observed in espionage operations targeting Western governments, journalists, think tanks, and NGOs between June and September, with IoCs and YARA rules published to aid detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
