Coldriver intensified high-profile espionage campaign
Campaign
Summary
Hide ▲
Show ▼
In October 2025, GTIG said Coldriver — also tracked as Star Blizzard, Callisto and UNC4057 — had moved from LostKeys to a new chain built around NoRobot, YesRobot and MaybeRobot, using a ClickFix-style lure, a fake CAPTCHA page, a malicious DLL launched with rundll32.exe, and downloads from inspectguarantee[.]org. In December 2025, researchers identified a fresh spear-phishing wave by Star Blizzard (ColdRiver/Calisto) against Reporters Without Borders (RSF) and another organization, using impersonated contacts, a custom AiTM kit on account.simpleasip[.]org, and attacker-controlled CAPTCHA and 2FA handling to harvest ProtonMail credentials. The activity shows continued phishing-driven espionage against high-value targets and a faster operational tempo after LostKeys was publicly disclosed in May 2025.
Related Happenings
UNC6508 China-linked REDCap espionage campaign
Campaign
H score39
First: 15.06.2026 17:00
Last: 15.06.2026 17:00
Sources 1
About this happening:
UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
UNC6508 China-linked REDCap espionage campaign
CampaignAbout this happening: UNC6508 ran a China-linked espionage campaign against exposed REDCap servers used by North American medical, academic, and military research networks. The operatio...
SHADOW-EARTH-053 China-aligned espionage campaign against Asian government and defense targets
Campaign
H score39
First: 01.05.2026 17:02
Last: 01.05.2026 17:02
Sources 1
About this happening:
SHADOW-EARTH-053 is running an active China-aligned espionage campaign against government and defense targets across South, East, and Southeast Asia and Poland...
SHADOW-EARTH-053 China-aligned espionage campaign against Asian government and defense targets
CampaignAbout this happening: SHADOW-EARTH-053 is running an active China-aligned espionage campaign against government and defense targets across South, East, and Southeast Asia and Poland...
UNC6783 BPO compromise campaign targeting downstream companies
Campaign
H score65
First: 09.04.2026 00:46
Last: 09.04.2026 00:46
Sources 1
About this happening:
UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
UNC6783 BPO compromise campaign targeting downstream companies
CampaignAbout this happening: UNC6783 is an active BPO compromise campaign targeting business process outsourcers and large enterprises to reach downstream environments for extortion. The opera...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
Campaign
H score34
First: 11.03.2026 16:45
Last: 11.03.2026 16:45
Sources 1
About this happening:
A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
Compromised legitimate WordPress websites used to infect visitors with infostealer malware campaign expands across multiple victims
CampaignAbout this happening: A global ClickFix campaign is abusing compromised WordPress sites to push infostealer malware to visitors, putting credentials and financial data at risk. The operatio...
CRESCENTHARVEST malicious .LNK espionage campaign targeting Iran protest supporters
Campaign
H score33
First: 19.02.2026 10:13
Last: 19.02.2026 10:13
Sources 1
About this happening:
The CRESCENTHARVEST campaign is using malicious .LNK files and social engineering to target supporters of Iran's ongoing protests for information theft and long-...
CRESCENTHARVEST malicious .LNK espionage campaign targeting Iran protest supporters
CampaignAbout this happening: The CRESCENTHARVEST campaign is using malicious .LNK files and social engineering to target supporters of Iran's ongoing protests for information theft and long-...
Timeline
-
03.12.2025 18:45 1 articles · 7mo ago
Star Blizzard spear-phishing wave targets RSF and another organization
Technical Analysis UpdateStar Blizzard, also known as ColdRiver or Calisto, was identified in a fresh spear-phishing wave against Reporters Without Borders (RSF) and another organization. The operators used impersonated trusted contacts, a custom Adversary-in-the-Middle (AiTM) kit on account.simpleasip[.]org, modified ProtonMail interface elements, and attacker-controlled API handling for CAPTCHA and two-factor authentication (2FA) to harvest credentials.
Show sources
- French NGO Reporters Without Borders Targeted by Star Blizzard — www.infosecurity-magazine.com — 03.12.2025 18:45
-
21.10.2025 13:02 2 articles · 8mo ago
Coldriver shifts to NoRobot, YesRobot and MaybeRobot
Initial DisclosureGTIG said Coldriver, also tracked as Star Blizzard, Callisto and UNC4057, had moved from LostKeys to a new malware chain built around NoRobot, YesRobot and MaybeRobot. The chain uses a ClickFix-style phishing lure, a fake CAPTCHA page, a malicious DLL launched via rundll32.exe, and downloads from inspectguarantee[.]org, while also reflecting a faster development and operations tempo in espionage operations against high-profile NGOs, former intelligence and military officers, and NATO governments.
Show sources
- Russian Coldriver Hackers Deploy New 'NoRobot' Malware — www.infosecurity-magazine.com — 21.10.2025 13:02
- Russian Coldriver Hackers Deploy New 'NoRobot' Malware — www.infosecurity-magazine.com — 21.10.2025 13:02