Microsoft and the US Department of Justice ( DOJ) have seized over 100 domains used by Russian hackers ColdRiver to target United States government employees and organizations around the world (via spear-phishing attacks).

In December, the UK and its Five Eyes allies linked this group to Russia's Federal Security Service (FSB), the country's internal security and counterintelligence agency
Russian hackers ColdRiver are said to have attacked American companies, former and current employees of the United States Intelligence Community, the Department of Defense, and the Department of State, as well as personnel from the U.S. Department of Energy and the Department of Defense.
See also: Russian hackers target Ukrainian military infrastructure
“Between January 2023 and August 2024, Microsoft observed that hackers targeted over 30 civil society organizations – journalists, think tanks, and non-governmental organizations (NGOs) working to ensure the well-being of democracy – deploying spear-phishing to steal sensitive information and disrupt their operations,” said Steven Masada, Assistant General Counsel in Microsoft’s Digital Crimes Unit.
Together, Microsoft and the DOJ seized 107 domains, dismantling the attack infrastructure used by Russian hackers ColdRiver.
According to Deputy Attorney General Lisa Monaco, the Russian government used the attacks by these hackers to steal sensitive information from Americans.
“The seizure of the domains is part of a coordinated response to disrupt the infrastructure that cyberespionage to attack American and international targets,” added U.S. Attorney Ismail J. Ramsey.
This intervention exemplifies the critical importance of collaboration between the private sector and law enforcement in addressing the complex and evolving landscape of cybersecurity threats.
See also: Russian GRU hackers attack critical infrastructure
As cyber threats continue to increase in complexity and frequency, constant vigilance and proactive strategies remain essential to protect sensitive data and maintain the integrity of national and international infrastructure.
However, both users and organizations should take steps to stay safe. Some of these include regularly passwords, avoiding suspicious emails or links, and using two-factor authentication whenever possible. By taking proactive steps to protect our personal information and being aware of potential threats, we can help create a safer digital world for ourselves and others.

ColdRiver hackers
The Russian hackers ColdRiver are also known as Callisto Group, Seaborgium, and Star Blizzard and have been active since at least 2017.
Government agencies, part of the Five Eyes alliance, warned in December 2023 about ColdRiver's spear-phishing attacks against academia, the defense sector, government organizations, NGOs, think tanks, and politicians.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Russian hackers suspected of cyberattack on Deutsche Flugsicherung
Microsoft has thwarted attacks by hackers against European NATO countriesby disabling Microsoft accounts they were using to collect emails and monitor their victims' activity.
In December, the US State Department imposed sanctions on two members of ColdRiver.
The State Department is offering up to $10 million for information that could help locate or identify other members of the group.
Source: www.bleepingcomputer.com
