Google: Russian FSB hackers deploy new Spica backdoor malware
ID: f096fc72-6fa1-5702-99e7-2f445b74deb3
STIX ID: report--f096fc72-6fa1-5702-99e7-2f445b74deb3
Feed Name: Bleeping Computer
Google TAG attributes a phishing campaign to the Russian-backed ColdRiver (aka Callisto/Seaborgium) group that lures targets with apparently encrypted PDF documents and a fake "Proton-decrypter.exe"; the executable contains a Rust-based backdoor named Spica which communicates over JSON/WebSockets, executes arbitrary shell commands, steals browser cookies (Chrome/Firefox/Opera/Edge), uploads/downloads files, exfiltrates documents, and establishes persistence via an obfuscated PowerShell-created 'CalendarChecker' scheduled task. Google added related domains/files to Safe Browsing, notified targeted Gmail/Workspace users, and researchers link ColdRiver to Russia's FSB Centre 18, with observed activity dating back to at least November 2022 (TAG observed Spica as early as September 2023).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
