EXECUTIVE SUMMARY
A spear phishing campaign has been targeting both Western and Russian civil society, leveraging highly personalized social engineering techniques. This campaign, identified through a collaborative with Access Now and other civil society organizations, primarily focuses on gaining unauthorized access to online accounts. The threat actor attributed to this campaign, COLDRIVER, also known as Star Blizzard and Callisto, is connected to the Russian Federal Security Service according to multiple government reports. A secondary threat actor, named COLDWASTREL, has been identified as targeting similar communities, aligning with Russian government interests.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A spear phishing campaign has been targeting both Western and Russian civil society, leveraging highly personalized social engineering techniques. This campaign, identified through a collaborative with Access Now and other civil society organizations, primarily focuses on gaining unauthorized access to online accounts. The threat actor attributed to this campaign, COLDRIVER, also known as Star Blizzard and Callisto, is connected to the Russian Federal Security Service according to multiple government reports. A secondary threat actor, named COLDWASTREL, has been identified as targeting similar communities, aligning with Russian government interests.[emaillocker id="1283"]
The attack flow typically involves initiating email exchanges where the threat actor impersonates known contacts, such as colleagues or funders, and includes requests to review documents. The emails often contain PDF attachments purportedly requiring encryption or protection, which, when clicked, redirect the target to phishing pages. These pages are designed to capture login credentials through spoofed login forms for services like Gmail or ProtonMail. The infrastructure for this campaign includes domains registered with Hostinger, which rotate IP addresses frequently to evade detection. Additionally, fingerprinting techniques are used to tailor the attack based on the target's system characteristics, and the use of JavaScript obfuscation is employed to obscure the attack code.
The River of Phish campaign highlights a significant and evolving threat in spear phishing, demonstrating advanced techniques in social engineering and technical execution. The correlation between this campaign's tactics, techniques, and procedures with known activities of COLDRIVER reinforces the attribution to this threat actor. The identification of COLDWASTREL as a separate entity targeting similar sectors underscores the ongoing and diverse nature of threats linked to geopolitical interests. Continued vigilance and cooperation among organizations are essential for addressing and mitigating these phishing campaigns.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Reconnaissance | T1589 | Gather Victim Identity Information |
| Resource Development | T1583 | Acquire Infrastructure |
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| Defense Evasion | T1027 | Obfuscated Files or Information |
| T1140 | Deobfuscate/Decode Files or Information | |
| T1078 | Valid Accounts | |
| Credential Access | T1539 | Steal Web Session Cookie |
| Collection | T1056 | Input Capture |
| Command and Control | T1102 | Web Service |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/08/russian-linked-hackers-target-eastern.html