logo

To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER

ID: 479df58c-d358-5fa3-ab91-b83e05254d13

STIX ID: report--479df58c-d358-5fa3-ab91-b83e05254d13

Feed Name: Threat Intelligence

Threat Score
85/100

Date Published: 2025-10-20

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

GTIG observed COLDRIVER deploying a simplified NOROBOT downloader that establishes persistence via a logon script which fetches a heavily obfuscated PowerShell payload (MAYBEROBOT/SIMPLEFIX). MAYBEROBOT implements a hardcoded C2 and a small custom protocol to download/execute payloads, run cmd.exe commands, or execute PowerShell blocks; GTIG documents the malware’s evolution, operational changes to evade detection, and provides IOCs and YARA rules to aid defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.