Threat Advisory

Russian-Linked Hackers Target Eastern European NGOs and Media

Threat: Phishing Campaign
Threat Actor Name: Callisto Group & COLDWASTREL
Targeted Region: Eastern Europe
Alias: Gossamer Bear, UNC4057, Seaborgium/Star Blizzard, TA446, TAG-53/BlueCharlie, Cobalt Edgewater/Iron Frontier, Blue Callisto, Coldriver
Threat Actor Region: Russia
Targeted Sector: Government & Defense, Critical Infrastructure
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A spear phishing campaign has been targeting both Western and Russian civil society, leveraging highly personalized social engineering techniques. This campaign, identified through a collaborative with Access Now and other civil society organizations, primarily focuses on gaining unauthorized access to online accounts. The threat actor attributed to this campaign, COLDRIVER, also known as Star Blizzard and Callisto, is connected to the Russian Federal Security Service according to multiple government reports. A secondary threat actor, named COLDWASTREL, has been identified as targeting similar communities, aligning with Russian government interests.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A spear phishing campaign has been targeting both Western and Russian civil society, leveraging highly personalized social engineering techniques. This campaign, identified through a collaborative with Access Now and other civil society organizations, primarily focuses on gaining unauthorized access to online accounts. The threat actor attributed to this campaign, COLDRIVER, also known as Star Blizzard and Callisto, is connected to the Russian Federal Security Service according to multiple government reports. A secondary threat actor, named COLDWASTREL, has been identified as targeting similar communities, aligning with Russian government interests.[emaillocker id="1283"]

 

The attack flow typically involves initiating email exchanges where the threat actor impersonates known contacts, such as colleagues or funders, and includes requests to review documents. The emails often contain PDF attachments purportedly requiring encryption or protection, which, when clicked, redirect the target to phishing pages. These pages are designed to capture login credentials through spoofed login forms for services like Gmail or ProtonMail. The infrastructure for this campaign includes domains registered with Hostinger, which rotate IP addresses frequently to evade detection. Additionally, fingerprinting techniques are used to tailor the attack based on the target's system characteristics, and the use of JavaScript obfuscation is employed to obscure the attack code.

 

The River of Phish campaign highlights a significant and evolving threat in spear phishing, demonstrating advanced techniques in social engineering and technical execution. The correlation between this campaign's tactics, techniques, and procedures with known activities of COLDRIVER reinforces the attribution to this threat actor. The identification of COLDWASTREL as a separate entity targeting similar sectors underscores the ongoing and diverse nature of threats linked to geopolitical interests. Continued vigilance and cooperation among organizations are essential for addressing and mitigating these phishing campaigns.

THREAT PROFILE:

Tactic Technique Id Technique
Reconnaissance T1589 Gather Victim Identity Information
Resource Development T1583 Acquire Infrastructure
 Initial Access T1566 Phishing
Execution T1204 User Execution
 Defense Evasion T1027 Obfuscated Files or Information
T1140 Deobfuscate/Decode Files or Information
T1078 Valid Accounts
Credential Access T1539 Steal Web Session Cookie
 Collection T1056 Input Capture
 Command and Control T1102 Web Service
 Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/08/russian-linked-hackers-target-eastern.html

[/emaillocker]
crossmenu