ColdRiver, a Russian spy group, known for stealing credentials, now uses poisoned PDFs in phishing attacks. Google warns of new tactics. (Getty Images)


January 22, 2024

In a recent report, Google's Threat Analysis Group (TAG) has issued a warning about a Russian-based espionage group, commonly known as ColdRiver, UNC4057, Star Blizzard, or Callisto, infamous for pilfering login credentials from government and military officials. The group has expanded its tactics by incorporating poisoned PDF attachments in phishing messages, leading unsuspecting victims to unwittingly download malware.

ColdRiver typically targets high-profile individuals within non-governmental organizations, such as think tanks, universities, former intelligence and military officers, NATO governments, and Ukraine. To carry out their schemes, the group creates deceptive online personas, posing as experts or individuals associated with the target. This impersonation tactic aims to establish a connection with the target, thereby increasing the success rate of their phishing campaigns.

According to TAG, ColdRiver has been observed sending benign PDF documents to targets since November 2022. These documents are presented as new op-eds or articles seeking feedback from the target. When opened, the benign PDF appears encrypted. If the target expresses difficulty reading the document, ColdRiver responds with a link to a supposed 'decryption' utility hosted on a cloud storage site. Unbeknownst to the victim, this utility is, in fact, a backdoor named SPICA, granting ColdRiver unauthorized access to the victim's machine.

While SPICA was first detected in September, Google believes it was utilized nearly a year prior, marking the first custom malware attributed to ColdRiver. This backdoor, developed in Rust, utilizes JSON over websockets for command and control, allowing it to steal browser cookies, upload and download files, and list the contents of file systems. The backdoor ensures persistence through an obfuscated PowerShell command, creating a scheduled task named CalendarChecker.

The report also provides the latest indicators of compromise to aid organizations in identifying potential threats. Notably, ColdRiver made headlines recently for allegedly targeting three U.S. nuclear research laboratories—Brookhaven (BNL), Argonne (ANL), and Lawrence Livermore National Laboratories (LLNL) in 2023. Reports suggest that the hackers employed fake login pages and emails to nuclear scientists, attempting to extract their passwords.

Microsoft, among other cybersecurity firms, has been actively working to disrupt ColdRiver, referring to them as Star Blizzard. In a December report, Microsoft highlighted the group's efforts to enhance its detection evasion capabilities, emphasizing the ongoing battle between cybersecurity entities and sophisticated threat actors like ColdRiver.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Google developing 'AI Replies' feature for Pixel Phone app

Google is reportedly working on a new "AI Replies" feature for its Phone app on Pixel smartphones, which will use....

Amazon wins FAA approval for new delivery drone, testing in Arizona

Amazon announced on Tuesday that it received regulatory approval from the Federal Aviation Administration (FAA) to begin flying a new,....

Apple is set to release new AI features for the holiday season

Apple has officially launched its much-anticipated generative AI software, Apple Intelligence, with the first set of features going live on....

Perplexity launches AI-based hub for election information

Perplexity, an innovative company specializing in AI search technology, has introduced a new platform designed to provide essential information to....

Chinese researchers create AI model for military using Meta's Llama

Chinese research institutions tied to the People's Liberation Army (PLA) have reportedly developed a military-focused AI tool using Meta's publicly....

OpenAI partners with Broadcom and TSMC to create new chip

OpenAI is making significant strides in its efforts to enhance its artificial intelligence capabilities by collaborating with Broadcom and TSMC....

Meta creates AI search tool to reduce dependence on Google, Bing

Meta Platforms is making significant strides in the artificial intelligence (AI) sector by developing its own AI-powered search engine, aiming....

Google Developing AI to Take Control of Computers, Says Report

Google is making strides in artificial intelligence with a new project aimed at transforming how we interact with web browsers.....

OpenAI set to launch new AI model Orion by December

OpenAI is gearing up to release its highly anticipated AI model, Orion, sometime in December. However, unlike previous versions like....

Nvidia unveils Hindi AI model to boost growth for Indian firms

Nvidia, a global leader in chip technology, has introduced a new, lightweight AI model designed specifically for Hindi, India’s most....

Google Chrome update introduces article reading feature for users

Google has rolled out a major update to its Chrome browser on Android, significantly enhancing the "Listen to this page"....

Anthropic launches AI tool to automate mouse clicks for coders

Anthropic, a startup backed by Alphabet and Amazon, has introduced updated artificial intelligence models, adding a feature designed to automate....