logo

Google says Russian espionage crew behind new malware campaign

ID: 03b90c4b-c937-5d7e-aeaa-11d238a1a045

STIX ID: report--03b90c4b-c937-5d7e-aeaa-11d238a1a045

Feed Name: TechCrunch Security News

Threat Score
85/100

Date Published: 2024-01-18

Date Updated: 2026-04-23

Author: Carly Page

...
...

Google's Threat Analysis Group reports that the Russian-linked APT Cold River has shifted from phishing to using benign-looking PDFs as lures to deliver a custom backdoor named SPICA. The malware provides persistent access, command execution, browser cookie theft and document exfiltration; targets include Ukraine, NATO allies, academic institutions and NGOs, and Google added identified sites and files to Safe Browsing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.