Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware
ID: 6272018f-0a7d-551a-b862-d238bf271051
STIX ID: report--6272018f-0a7d-551a-b862-d238bf271051
Feed Name: The Hacker News
The Russia-linked APT COLDRIVER (aka Calisto/Blue Callisto/TA446) has evolved from credential harvesting to deploying a custom Rust backdoor named SPICA delivered via PDF lures and a purported "Proton-decrypter.exe" hosted on cloud storage; SPICA provides C2 via JSON over WebSockets, arbitrary command execution, cookie theft, file transfer and persistence, and appears to have been used in limited targeted operations against high-value targets (NGOs, former intelligence/military officials, defense and NATO governments). Google TAG and others analyzed the campaign, added related infrastructure to Safe Browsing blocklists, and U.S./U.K. sanctions have targeted individuals linked to the group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
