Google says Russian espionage crew behind new malware campaign
ID: 03b90c4b-c937-5d7e-aeaa-11d238a1a045
STIX ID: report--03b90c4b-c937-5d7e-aeaa-11d238a1a045
Feed Name: TechCrunch Security News
Threat Score
Google's Threat Analysis Group reports that the Russian-linked APT Cold River has shifted from phishing to using benign-looking PDFs as lures to deliver a custom backdoor named SPICA. The malware provides persistent access, command execution, browser cookie theft and document exfiltration; targets include Ukraine, NATO allies, academic institutions and NGOs, and Google added identified sites and files to Safe Browsing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
