ColdRiver, a Russian spy group, known for stealing credentials, now uses poisoned PDFs in phishing attacks. Google warns of new tactics. (Getty Images)


January 22, 2024

In a recent report, Google's Threat Analysis Group (TAG) has issued a warning about a Russian-based espionage group, commonly known as ColdRiver, UNC4057, Star Blizzard, or Callisto, infamous for pilfering login credentials from government and military officials. The group has expanded its tactics by incorporating poisoned PDF attachments in phishing messages, leading unsuspecting victims to unwittingly download malware.

ColdRiver typically targets high-profile individuals within non-governmental organizations, such as think tanks, universities, former intelligence and military officers, NATO governments, and Ukraine. To carry out their schemes, the group creates deceptive online personas, posing as experts or individuals associated with the target. This impersonation tactic aims to establish a connection with the target, thereby increasing the success rate of their phishing campaigns.

According to TAG, ColdRiver has been observed sending benign PDF documents to targets since November 2022. These documents are presented as new op-eds or articles seeking feedback from the target. When opened, the benign PDF appears encrypted. If the target expresses difficulty reading the document, ColdRiver responds with a link to a supposed 'decryption' utility hosted on a cloud storage site. Unbeknownst to the victim, this utility is, in fact, a backdoor named SPICA, granting ColdRiver unauthorized access to the victim's machine.

While SPICA was first detected in September, Google believes it was utilized nearly a year prior, marking the first custom malware attributed to ColdRiver. This backdoor, developed in Rust, utilizes JSON over websockets for command and control, allowing it to steal browser cookies, upload and download files, and list the contents of file systems. The backdoor ensures persistence through an obfuscated PowerShell command, creating a scheduled task named CalendarChecker.

The report also provides the latest indicators of compromise to aid organizations in identifying potential threats. Notably, ColdRiver made headlines recently for allegedly targeting three U.S. nuclear research laboratories—Brookhaven (BNL), Argonne (ANL), and Lawrence Livermore National Laboratories (LLNL) in 2023. Reports suggest that the hackers employed fake login pages and emails to nuclear scientists, attempting to extract their passwords.

Microsoft, among other cybersecurity firms, has been actively working to disrupt ColdRiver, referring to them as Star Blizzard. In a December report, Microsoft highlighted the group's efforts to enhance its detection evasion capabilities, emphasizing the ongoing battle between cybersecurity entities and sophisticated threat actors like ColdRiver.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

The Onion Eyes Infowars Takeover Deal

A surprising development is unfolding in the ongoing legal and financial battle surrounding Infowars, as satirical outlet The Onion moves....

Artemis II Mission Ends in Dramatic Splashdown, Marking Historic Return to Lunar Exploration

The Artemis II mission concluded with a dramatic splashdown in the Pacific Ocean, bringing home the first crewed lunar journey....

Artemis II Astronauts Break Apollo 13 Record, Emotional Moment Follows Historic Milestone

The Artemis II astronauts marked a historic achievement in space exploration, surpassing the distance record set by Apollo 13, in....

Artemis II Moon Mission Launch Marks Historic Return to Deep Space Exploration

The Artemis II moon mission has successfully launched from Florida, sending four astronauts on a landmark journey around the moon....

Musk Plans to Build ‘Terafab’ Chip Factories in Austin

Elon Musk has revealed ambitious plans to build a next-generation chip manufacturing hub in Texas, signaling a major push to....

NASA Clears Artemis II Moon Mission for April Launch

NASA has cleared its powerful Space Launch System rocket for an April launch, paving the way for humanity’s first crewed....

Meta Buys AI Bot Network Moltbook

Meta Platforms has acquired Moltbook, a newly launched social network where artificial intelligence agents interact with one another autonomously. The....

Robot Boom Ahead? Canadian Firm Eyes AI Factory Future

The race to build smarter, more capable humanoid robots is heating up worldwide, and a small Canadian company believes it....

Cheap Laptops Challenge MacBook Neo With More Storage and Memory

Apple has stepped into the budget laptop segment with the launch of the MacBook Neo, priced at $599. On paper,....

Apple iPhone 17e Leads Apple Product Launch Week With M4 iPad Air Update

Apple has kicked off a fresh round of hardware announcements with a clear focus on value and performance. The company....

Viral AI Caricature Trend Sparks Serious Privacy Fears, Expert Warns

A viral social media trend that turns personal details into AI-generated caricatures is raising red flags among cybersecurity experts, who....

India AI Impact Summit 2026: Global Leaders, CEOs Gather in New Delhi for High-Stakes Talks

India has opened a major global gathering focused on artificial intelligence and its growing worldwide influence. The India AI Impact....