logo

Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware

ID: 6272018f-0a7d-551a-b862-d238bf271051

STIX ID: report--6272018f-0a7d-551a-b862-d238bf271051

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-01-18

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The Russia-linked APT COLDRIVER (aka Calisto/Blue Callisto/TA446) has evolved from credential harvesting to deploying a custom Rust backdoor named SPICA delivered via PDF lures and a purported "Proton-decrypter.exe" hosted on cloud storage; SPICA provides C2 via JSON over WebSockets, arbitrary command execution, cookie theft, file transfer and persistence, and appears to have been used in limited targeted operations against high-value targets (NGOs, former intelligence/military officials, defense and NATO governments). Google TAG and others analyzed the campaign, added related infrastructure to Safe Browsing blocklists, and U.S./U.K. sanctions have targeted individuals linked to the group.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.