HomeSecurityGoogle: Reveals tactics of Russian hacking group 'Cold River'

Google: Reveals tactics of Russian hacking group 'Cold River'

Google researchers say they have evidence of a well-known Russian-linked hacker group known as “Cold River” that is evolving its tactics beyond phishing.

cold river

Its goal is to steal data through malware, targeting victims it encounters.

Cold River, also known as the “Callisto Group” and “Star Blizzard,” is known for conducting long-term espionage campaigns against NATO countries, particularly the United States and the United Kingdom.

Read also: Iranian hackers target researchers with custom malware

Investigators believe the group's activities, which typically target high-profile individuals and organizations involved in international affairs and defense, suggest close ties to the Russian state. In December, U.S. prosecutors indicted two Russian citizens associated with the group.

Threat Analysis Group (TAG) said in a new investigation this week that it has seen increased activity from Cold River in recent months and that it is using new tactics that are causing more disruption to its victims. Primary targets include Ukraine and its NATO allies, as well as academic institutions and non-governmental organizations.

These recent discoveries followed a report by Microsoft researchers , who revealed that the Russian-linked hacking group had improved its ability to evade detection

When the victim opens the “benevolent” PDF, the text appears encrypted. If the target states that they cannot read the document, the hacker will send a link that includes a “decryption” utility. Google researchers report that this program is known as “SPICA” and is a custom backdoor that is being monitored. Google identifies SPICA as the first custom malware developed and used by Cold River. This backdoor allows hackers to have constant access to the victim’s computer, allowing them to execute commands, steal browser cookies, and manipulate documents.

Billy Leonard, a security engineer at TAG, told TechCrunch that Google doesn’t know the exact number of victims successfully compromised by SPICA. However, the company believes that SPICA was only used in “limited and targeted attacks.” Billy Leonard added that the malware is likely still being developed and used in ongoing attacks, while Cold River’s activity has remained steady in recent years, despite law enforcement efforts.

cold river Russia

See also: Bigpanzi hackers: Their botnet targets Android TV boxes

Google researchers had previously linked the Cold River group to a hack-and-leak attack that resulted in the theft and leak of a large number of emails and documents. The targets of this attack were high-ranking Brexit supporters, including Sir Richard Dearlove, the former head of Britain's foreign intelligence service, MI6.

Source: techcrunch.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS