logo

COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs

ID: 26debac9-2ef8-58ba-aa91-04d0cb3bbd1c

STIX ID: report--26debac9-2ef8-58ba-aa91-04d0cb3bbd1c

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-05-07

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

Google Threat Intelligence Group (GTIG) reports that the Russian government‑linked APT COLDRIVER (aka UNC4057/Star Blizzard) deployed a new infostealer named LOSTKEYS in 2025; LOSTKEYS exfiltrates files from specified directories and extensions, collects system information and running processes, and is delivered via a multi-step lure involving a fake CAPTCHA that triggers PowerShell execution—targets include high‑profile individuals, NGOs, journalists, and persons connected to Ukraine, consistent with intelligence‑collection objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.