Russian hackers COLDRIVER are distributing a new malware called LOSTKEYS, as part of an espionage campaign based on ClickFix-like social engineering.

According to the Google Threat Intelligence Group (GTIG), LOSTKEYS has the ability to steal files as well as send information about the victim's system and execute commands on behalf of the attacker.
See also: MintsLoader distributes GhostWeaver via Phishing, ClickFix
The malware was recorded in attacks carried out in January, March and April 2025, targeting active and former Western government advisers , members of the armed forces , journalists, research institutes and non-governmental organizations . In addition, individuals with ties to Ukraine were also targeted .
LOSTKEYS is the second custom malware attributed to the COLDRIVER group, following the SPICA. The group is also known by the names Callisto, Star Blizzard , and UNC4057.
As security researcher Wesley Shields, COLDRIVER has been linked to attacks that target credentials, which gain access to email accounts. From there, the group extracts contact lists and in some cases pushes malware to victims' devices, aiming to further infiltrate and access files.
See also: Lazarus hacker group adopts ClickFix attacks
ClickFix-like social engineering for LOSTKEYS distribution
The latest series of attacks begins with a malicious decoy website that displays a misleading CAPTCHA. Visitors to the website are tricked into opening the Windows Run and pasting a PowerShell command, which has already been automatically copied to their clipboard. This social engineering method is known as ClickFix and has become particularly popular among cybercriminals.
This PowerShell command is programmed to download and execute additional malicious content from a remote server (IP address: “165.227.148[.]68”). Before doing so, however, it checks whether it is running in a virtual machine environment, presumably to avoid detection by malware analysis systems.
See also: Fake Discord PyPI Package contains malware
The third stage of the attack involves a Base64-encoded blob, which is decoded into a new PowerShell script. This in turn triggers the LOSTKEYS on the infected computer. LOSTKEYS collects system data, active processes, and files with specific extensions and from predefined folders.
As was the case with the SPICA malware, LOSTKEYS appears to be used sparingly, suggesting that these attacks are targeted rather than mass.

Google also noted that other versions of LOSTKEYS were found dating back to December 2023. These variants were disguised as legitimate executables related to the open-source tool Maltego. However, it remains unclear whether these samples are directly linked to the COLDRIVER or whether the malware was also used by other attackers from January 2025 onwards.
Protection from ClickFix attacks and malware
- Educating users about social engineering tactics and phishing attacks
- Install (and update) antivirus and anti-malware software on all endpoints
- Implement powerful email filters to block phishing emails and malicious attachments
- Use of firewalls and intrusion detection/prevention systems (IDS/IPS)
- Network segmentation to limit the spread of malware
- Implementation of the principle of least privilege (PoLP), so that users only have access to necessary resources
- Multi-factor authentication (MFA) implementation
- Updating operating systems, software and applications
- Encryption of sensitive data
- Continuous monitoring and analysis of system and network logs
- Back up important data
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
