Close Menu
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
What's Hot

Telegram Founder Says France Offered Him Court Help in Exchange for Censorship

September 29, 2025

Etihad Airways Inaugurates First Flight Connecting Abu Dhabi and Peshawar | News

September 29, 2025

2026 New Year Goals Template: Free Goal Tracker

September 29, 2025
Facebook X (Twitter) Pinterest YouTube
Facebook X (Twitter) Pinterest YouTube
Mind Fortunes
Subscribe
  • Home
  • Psychology
  • Dating
    • Relationship
  • Spirituality
    • Manifestation
  • Health
    • Fitness
  • Lifestyle
  • Family
  • Food
  • Travel
  • More
    • Business
    • Education
    • Technology
Mind Fortunes
Home»Technology»New Russian Malware in Action
Technology

New Russian Malware in Action

May 10, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
New Russian Malware in Action
Share
Facebook Twitter LinkedIn Pinterest Email

The realm of cyber espionage has a new participant in the form of a stealthy malware known as “LostKeys.” Google has reported that a Russian state-backed group called COLDRIVER has been utilizing LostKeys since the beginning of this year to spy on Western governments, journalists, think tanks, and non-governmental organizations.

COLDRIVER is not a newcomer in the cyber espionage scene. In December, the UK and its intelligence allies known as “Five Eyes” pointed fingers at them. This hacking group has direct ties to Russia’s Federal Security Service (FSB), which is a significant player in counterintelligence and internal security.

Google’s Threat Intelligence Group (GTIG) detected LostKeys in January. COLDRIVER has been using this malware in targeted “ClickFix” attacks, which involve tricking individuals into running malicious PowerShell scripts through social engineering tactics. These scripts facilitate the download and execution of more malicious PowerShell commands, ultimately leading to the installation of LostKeys. Google has classified LostKeys as a Visual Basic Script (VBS) data theft malware that acts as a “digital vacuum cleaner,” extracting specific files and directories while sending system information back to the attackers.

COLDRIVER’s usual modus operandi includes stealing login credentials to access emails and contacts. Additionally, they have been known to deploy another malware called SPICA for document and file theft. LostKeys appears to serve a similar purpose but is reserved for “highly selective cases,” indicating its specialized role in COLDRIVER’s espionage activities.

Interestingly, COLDRIVER is not the only state-sponsored group utilizing ClickFix attacks. Groups associated with North Korea (Kimsuky), Iran (MuddyWater), and other Russian actors (APT28 and UNK_RemoteRogue) have also employed similar tactics in recent spying campaigns.

See also  iOS 19: All the rumored changes Apple could be bringing to its new operating system

COLDRIVER, also known as Star Blizzard and Callisto Group, has been perfecting their social engineering and open-source intelligence techniques since 2017. Their targets have included defense and government entities, NGOs, and politicians. Following Russia’s invasion of Ukraine, their attacks have escalated, expanding to defense-industrial sites and US Department of Energy facilities.

The US State Department has imposed sanctions on several COLDRIVER members, including an alleged FSB officer. A substantial $10 million reward is being offered by US authorities for any information leading to the apprehension of other group members, underscoring the seriousness with which the US views COLDRIVER.

Action Malware Russian
Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
Previous ArticleExplore the beautiful Costa Brava
Next Article How to Maximize Fit Between Coach and Coachee

Related Posts

Telegram Founder Says France Offered Him Court Help in Exchange for Censorship

September 29, 2025

The startup behind open source tool Polars raises $21M from Accel

September 29, 2025

Xiaomi 17 Series Breaks New Ground With 100W Universal Fast Charging

September 29, 2025

The billion-dollar infrastructure deals powering the AI boom

September 28, 2025

Comments are closed.

Our Picks
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Don't Miss
Technology

Telegram Founder Says France Offered Him Court Help in Exchange for Censorship

September 29, 20250

Telegram’s founder, Pavel Durov, faced arrest in France last year after alleging that the French…

Etihad Airways Inaugurates First Flight Connecting Abu Dhabi and Peshawar | News

September 29, 2025

2026 New Year Goals Template: Free Goal Tracker

September 29, 2025

The startup behind open source tool Polars raises $21M from Accel

September 29, 2025
About Us
About Us

Explore blogs on mind, spirituality, health, and travel. Find balance, wellness tips, inner peace, and inspiring journeys to nurture your body, mind, and soul.

We're accepting new partnerships right now.

Our Picks

Telegram Founder Says France Offered Him Court Help in Exchange for Censorship

September 29, 2025

Etihad Airways Inaugurates First Flight Connecting Abu Dhabi and Peshawar | News

September 29, 2025

2026 New Year Goals Template: Free Goal Tracker

September 29, 2025

Subscribe to Updates

Awaken Your Mind, Nourish Your Soul — Join Our Journey Today!

Facebook X (Twitter) Pinterest YouTube
  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2025 mindfortunes.org - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.