#YESROBOT
Star Blizzard's RedFlick needs one click to plant a Python backdoor via disguised scheduled tasks. https://intel.threadlinqs.com/threat/TL-2026-2787 #ThreatIntel #YESROBOT #NOROBOT #MAYBEROBOT
September 29, 2026 at 11:27 PM
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
September 18, 2025 at 4:29 PM
Too many kids getting wrapped up in groups like this. "three 17-year-old men have been suspected of providing services to a foreign government, with one of them alleged to be in contact with a hacker group affiliated with the Russian government." thehackernews.com/2025/10/goog...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 12:54 PM
Russian state-backed hackers Star Blizzard (aka #ColdRiver / Callisto / UNC4057) have ramped up ops, unleashing new malware — NOROBOT, YESROBOT, MAYBEROBOT — via ClickFix CAPTCHA-style lures. Victims think they’re proving they’re human — but end up running code. #CyberSecurity #APT
October 22, 2025 at 10:14 AM
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers thehackernews.com/2025/10/goog...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 22, 2025 at 4:12 PM
COLDRIVER re-tooled within days of LOSTKEYS - a fake CAPTCHA now drops its NOROBOT ClickFix chain. https://intel.threadlinqs.com/threat/TL-2026-1510 #ThreatIntel #NOROBOT #YESROBOT #MAYBEROBOT
July 19, 2026 at 7:17 AM
Google alerta sobre 3 novas ameaças cibernética criada por hackers russos
O Grupo de Inteligência de Ameaças do Google (GTIG) identificou uma nova e acelerada onda de desenvolvimento de malwares atribuída ao COLDRIVER — um grupo de hackers associado ao governo russo. A descoberta foi detalhada em uma publicação feita nesta segunda-feira (20), revelando o surgimento de três novas ameaças cibernéticas: NOROBOT, YESROBOT e MAYBEROBOT. De acordo com o Google, a **nova família de malwares passou por “múltiplas iterações” desde maio deste ano** , o que demonstra um ritmo acelerado de evolução e operação por parte do COLDRIVER. As variantes descobertas compartilham uma cadeia de distribuição interligada, sugerindo um esforço coordenado de aprimoramento técnico e escalabilidade. A instalação do malware acontece por meio do método ClickFix. (Fonte: Google/Reprodução) Tradicionalmente conhecido por empregar ataques de phishing para comprometer alvos e roubar dados sensíveis, o COLDRIVER parece agora expandir seu escopo. “Está claro que eles investiram esforços significativos em seu desenvolvimento para reequipar e implantar seu malware em alvos específicos”, afirmou o GTIG. O **grupo acredita que os novos malwares sejam usados para infectar vítimas previamente comprometidas** , cujos dados e contatos foram extraídos em campanhas anteriores. O COLDRIVER — **também identificado pelos nomes UNC4057, Star Blizzard e Callisto** — é patrocinado pelo Estado russo e costuma mirar indivíduos de alto perfil, como consultores políticos, dissidentes e integrantes de ONGs. O avanço observado nos últimos meses coincide com a descoberta do malware LOSTKEYS, revelado em maio, o que reforça a hipótese de uma nova fase de atuação do grupo. ## Como acontece a infecção? A infecção ocorre a partir de um anúncio falso chamado ClickFix, disfarçado sob o nome COLDCOPY. Ao clicar no aviso, o usuário inicia o download do malware NOROBOT, executado por meio do processo legítimo `rundll32.exe`. Esse arquivo, por sua vez, aciona o próximo estágio da cadeia de ataque. Em versões iniciais, o NOROBOT distribuía o backdoor YESROBOT. Nas iterações mais recentes, no entanto, o COLDRIVER substituiu o payload pelo MAYBEROBOT — uma versão mais avançada e versátil, capaz de baixar cargas a partir de URLs específicos, executar comandos via CMD e rodar códigos diretamente no PowerShell. Os **malwares NOROBOT e MAYBEROBOT também são monitorados pela empresa de cibersegurança Zscaler** **ThreatLabz** , mas com os nomes BAITSWITCH e SIMPLESFIX, respectivamente. ## Google alertou vítimas sobre a atividade irregular O Google segue monitorando a evolução da família de malwares, destacando a rapidez com que o COLDRIVER adaptou e expandiu suas ferramentas ofensivas em poucos meses. Como medida de contenção, todas as páginas, os domínios e os arquivos maliciosos encontrados durante a investigação foram adicionados à lista de restrição do Safe Browsing. Alvos antigos e potenciais vítimas também foram alertados. Quer saber mais sobre cibersegurança e ameaças digitais? Acompanhe o **TecMundo** para se manter atualizado sobre as mais recentes descobertas, vulnerabilidades e estratégias de proteção no mundo da tecnologia.
www.tecmundo.com.br
October 21, 2025 at 7:56 PM
‘I am not a robot’: Russian hackers use fake CAPTCHA lures to deploy espionage tools
Russian state-backed hackers are using fake “I am not a robot” CAPTCHA pages to deliver new strains of espionage malware, according to Google Cloud’s Threat Intelligence Group (GTIG), marking a fresh evolution in tactics by the ColdRiver group that has long targeted Western governments, think tanks, and media organizations. The group, also known as Star Blizzard, UNC4057, or Callisto, has replaced its previously exposed LostKeys malware with a new suite of tools, including NOROBOT, YESROBOT, and MAYBEROBOT. These programs can evade detection through multi-stage delivery chains and encrypted payloads. Google said the shift came just days after the company published technical details on LostKeys earlier this year. ColdRiver’s latest campaign uses social engineering tactics known as “ClickFix,” tricking victims into running malicious code disguised as CAPTCHA verification steps. “NOROBOT and its preceding infection chain have been subject to constant evolution — initially simplified to increase chances of successful deployment, before re-introducing complexity by splitting cryptography keys,” GTIG said. “The shift back to more complex delivery chains increases the difficulty of tracking their campaigns. This constant development highlights the group’s efforts to evade detection systems for their delivery mechanism for continued intelligence collection against high-value targets.” The technique shows a growing trend in state-sponsored operations that combine psychological manipulation with stealthy modular malware to bypass enterprise defenses. “ColdRiver’s quick pivot from exposed infrastructure to new delivery methods like fake CAPTCHAs reveals a lot about their capabilities,” said Akshat Tyagi, associate practice leader at HFS Research. “They are operationally very agile because, practically within weeks, they shifted infrastructure, rewrote delivery mechanisms, and deployed new payloads. It seems they are a well-funded and well-resourced team. They likely have a modular architecture allowing them to replace components, and they also have access to global engineering talent.” ## Inside the findings Google said the new malware families have been in active development from May through September 2025, with the attackers repeatedly refining their tools to evade detection. The pace of updates shows ColdRiver’s ability to rebuild its toolset almost immediately after public exposure. The earliest NOROBOT sample used a cryptographic scheme that split the decryption key across multiple components that had to be recombined in a specific order to decrypt the final payload. YESROBOT is described in Google’s report as a minimal Python backdoor that requires every command to be valid Python, making basic functions such as downloading files or retrieving documents more cumbersome to implement. The latter NOROBOT build was drastically simplified, fetching a single file that, in observed cases, installed a logon script to establish persistence. “The specific changes made between NOROBOT variants highlight the group’s persistent effort to evade detection systems while ensuring continued intelligence collection against high-value targets,” the report said. ## Evolving tactics and strategies Analysts said ColdRiver, which for years focused on credential theft and email account compromise, is shifting toward multi-stage intrusions that rely on users to execute malicious code. By using ClickFix pages that mimic CAPTCHA verification screens, the group can bypass email security filters and deliver malware directly to victims’ devices, increasing the likelihood of infection. “At this stage, it is difficult to expect end users to identify and discard fraudulent CAPTCHA, since CAPTCHA is part of the standard access process,” said cybersecurity analyst Sunil Varkey. “The only option is to monitor behavioral changes, living-off-the-land telemetry, and abnormal activity through tools such as EDR and NDR. Organizations need to understand how users and hosts behave in specific scenarios and monitor deviations, which requires having a strong baseline and enforcing it.” This shift from simple phishing to multi-stage, interactive attacks shows ColdRiver’s ability to adapt to improved cyber awareness among users. Traditional lures are less effective as people become cautious about clicking suspicious links, but CAPTCHA pages still feel familiar and safe, a trust ColdRiver has learned to exploit. “Tactically, it indicates ColdRiver’s focus on operational security (OPSEC) and stealth,” said Sanjaya Kumar, CEO of SureShield. “The malware uses encrypted communications and anti-analysis techniques, allowing prolonged access for months without detection. Target selection remains high value, including NGOs, dissidents, policy advisors, and Western officials, but the CAPTCHA method also extends to softer targets in think tanks and academia, where quick credential theft can lead to espionage chains.” For defenders, it underscores the need to move beyond traditional two-factor authentication and adopt behavioral and context-aware monitoring to identify stealthy, user-assisted intrusions. ## Defense options for enterprises Because the attackers target specific organizations and individuals, they can use server-side filtering to deliver malware only to selected victims, making large-scale detection difficult, analysts said. Detection is further complicated when global security vendors have not yet developed or prioritized signatures for the new attacks. “Defenders need to be fully aware that this isn’t a basic phishing gang using off-the-shelf malware,” Varkey said. “It appears to be state-linked or state-sponsored, with significant resources and the ability to pivot to new tools and delivery methods rapidly. Defenders cannot depend solely on IOCs, and organizations may need to strengthen their security posture to protect high-value assets significantly.” Kumar added that effective defense requires a layered and behavior-focused approach that uses tools to monitor anomalous PowerShell execution, unusual network calls to command-and-control servers, or fileless malware patterns. Security teams should establish baselines for normal activity and generate alerts when deviations occur, such as unexpected login attempts from foreign IP addresses or rapid data exfiltration. “Focus on building a zero-trust architecture and enforce least-privilege access and micro-segmentation to limit lateral movement,” Kumar said. “Continuous vulnerability management scans to patch endpoints before exploitation, combined with security awareness training on interactive phishing (e.g., simulated CAPTCHA attacks), to cut success rates. Incident Responses need to be solidified, so simulate multi-stage attacks to test containment. Proactive cyber hygiene – regular patching, endpoint hardening, and threat hunting is essential.”
www.csoonline.com
October 23, 2025 at 2:54 PM
‘I am not a robot’: Russian hackers use fake CAPTCHA lures to deploy espionage tools
Russian state-backed hackers are using fake “I am not a robot” CAPTCHA pages to deliver new strains of espionage malware, according to Google Cloud’s Threat Intelligence Group (GTIG), marking a fresh evolution in tactics by the ColdRiver group that has long targeted Western governments, think tanks, and media organizations. The group, also known as Star Blizzard, UNC4057, or Callisto, has replaced its previously exposed LostKeys malware with a new suite of tools, including NOROBOT, YESROBOT, and MAYBEROBOT. These programs can evade detection through multi-stage delivery chains and encrypted payloads. Google said the shift came just days after the company published technical details on LostKeys earlier this year. ColdRiver’s latest campaign uses social engineering tactics known as “ClickFix,” tricking victims into running malicious code disguised as CAPTCHA verification steps. “NOROBOT and its preceding infection chain have been subject to constant evolution — initially simplified to increase chances of successful deployment, before re-introducing complexity by splitting cryptography keys,” GTIG said. “The shift back to more complex delivery chains increases the difficulty of tracking their campaigns. This constant development highlights the group’s efforts to evade detection systems for their delivery mechanism for continued intelligence collection against high-value targets.” The technique shows a growing trend in state-sponsored operations that combine psychological manipulation with stealthy modular malware to bypass enterprise defenses. “ColdRiver’s quick pivot from exposed infrastructure to new delivery methods like fake CAPTCHAs reveals a lot about their capabilities,” said Akshat Tyagi, associate practice leader at HFS Research. “They are operationally very agile because, practically within weeks, they shifted infrastructure, rewrote delivery mechanisms, and deployed new payloads. It seems they are a well-funded and well-resourced team. They likely have a modular architecture allowing them to replace components, and they also have access to global engineering talent.” ## Inside the findings Google said the new malware families have been in active development from May through September 2025, with the attackers repeatedly refining their tools to evade detection. The pace of updates shows ColdRiver’s ability to rebuild its toolset almost immediately after public exposure. The earliest NOROBOT sample used a cryptographic scheme that split the decryption key across multiple components that had to be recombined in a specific order to decrypt the final payload. YESROBOT is described in Google’s report as a minimal Python backdoor that requires every command to be valid Python, making basic functions such as downloading files or retrieving documents more cumbersome to implement. The latter NOROBOT build was drastically simplified, fetching a single file that, in observed cases, installed a logon script to establish persistence. “The specific changes made between NOROBOT variants highlight the group’s persistent effort to evade detection systems while ensuring continued intelligence collection against high-value targets,” the report said. ## Evolving tactics and strategies Analysts said ColdRiver, which for years focused on credential theft and email account compromise, is shifting toward multi-stage intrusions that rely on users to execute malicious code. By using ClickFix pages that mimic CAPTCHA verification screens, the group can bypass email security filters and deliver malware directly to victims’ devices, increasing the likelihood of infection. “At this stage, it is difficult to expect end users to identify and discard fraudulent CAPTCHA, since CAPTCHA is part of the standard access process,” said cybersecurity analyst Sunil Varkey. “The only option is to monitor behavioral changes, living-off-the-land telemetry, and abnormal activity through tools such as EDR and NDR. Organizations need to understand how users and hosts behave in specific scenarios and monitor deviations, which requires having a strong baseline and enforcing it.” This shift from simple phishing to multi-stage, interactive attacks shows ColdRiver’s ability to adapt to improved cyber awareness among users. Traditional lures are less effective as people become cautious about clicking suspicious links, but CAPTCHA pages still feel familiar and safe, a trust ColdRiver has learned to exploit. “Tactically, it indicates ColdRiver’s focus on operational security (OPSEC) and stealth,” said Sanjaya Kumar, CEO of SureShield. “The malware uses encrypted communications and anti-analysis techniques, allowing prolonged access for months without detection. Target selection remains high value, including NGOs, dissidents, policy advisors, and Western officials, but the CAPTCHA method also extends to softer targets in think tanks and academia, where quick credential theft can lead to espionage chains.” For defenders, it underscores the need to move beyond traditional two-factor authentication and adopt behavioral and context-aware monitoring to identify stealthy, user-assisted intrusions. ## Defense options for enterprises Because the attackers target specific organizations and individuals, they can use server-side filtering to deliver malware only to selected victims, making large-scale detection difficult, analysts said. Detection is further complicated when global security vendors have not yet developed or prioritized signatures for the new attacks. “Defenders need to be fully aware that this isn’t a basic phishing gang using off-the-shelf malware,” Varkey said. “It appears to be state-linked or state-sponsored, with significant resources and the ability to pivot to new tools and delivery methods rapidly. Defenders cannot depend solely on IOCs, and organizations may need to strengthen their security posture to protect high-value assets significantly.” Kumar added that effective defense requires a layered and behavior-focused approach that uses tools to monitor anomalous PowerShell execution, unusual network calls to command-and-control servers, or fileless malware patterns. Security teams should establish baselines for normal activity and generate alerts when deviations occur, such as unexpected login attempts from foreign IP addresses or rapid data exfiltration. “Focus on building a zero-trust architecture and enforce least-privilege access and micro-segmentation to limit lateral movement,” Kumar said. “Continuous vulnerability management scans to patch endpoints before exploitation, combined with security awareness training on interactive phishing (e.g., simulated CAPTCHA attacks), to cut success rates. Incident Responses need to be solidified, so simulate multi-stage attacks to test containment. Proactive cyber hygiene – regular patching, endpoint hardening, and threat hunting is essential.”
www.csoonline.com
October 22, 2025 at 12:42 PM
A new malware attributed to the Russia-linked hacking group known as COLDRIVER has undergone numerous developmental iterations since May 2025, suggesting an increased "operations tempo" from the threat actor. thehackernews.com/2025/10/go...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 3:00 PM
Russia-Linked COLDRIVER Backdoor Evolves: From NOROBOT to MAYBEROBOT Targeting NGOs and Dissidents

In a chilling development in cyber espionage, Russia-linked hacking group COLDRIVER has advanced its malware capabilities, moving from its earlier NOROBOT backdoor to YESROBOT and now the latest…
Russia-Linked COLDRIVER Backdoor Evolves: From NOROBOT to MAYBEROBOT Targeting NGOs and Dissidents
In a chilling development in cyber espionage, Russia-linked hacking group COLDRIVER has advanced its malware capabilities, moving from its earlier NOROBOT backdoor to YESROBOT and now the latest variant, MAYBEROBOT. This evolution highlights a growing focus on NGOs, policy advisors, and dissident communities, marking a dangerous escalation in targeted cyber operations against civil society actors. Security analysts have traced multiple domains, IP addresses, and email-linked WHOIS records connected to these attacks, signaling a sophisticated infrastructure supporting the campaign.
undercodenews.com
November 26, 2025 at 10:20 PM
ColdRiver’s Rapid Malware Evolution: A New Era in Cyber Espionage

In a striking demonstration of adaptability and persistence, the Russian state-sponsored hacking group known as ColdRiver has swiftly evolved its malware arsenal following the public exposure of its previous tool, LOSTKEYS, in May…
ColdRiver’s Rapid Malware Evolution: A New Era in Cyber Espionage
In a striking demonstration of adaptability and persistence, the Russian state-sponsored hacking group known as ColdRiver has swiftly evolved its malware arsenal following the public exposure of its previous tool, LOSTKEYS, in May 2025. Within just five days of the disclosure, ColdRiver deployed a new suite of malware families—NOROBOT, YESROBOT, and MAYBEROBOT—marking a significant shift in their cyber espionage tactics. These developments underscore the group's commitment to maintaining operational continuity and enhancing the sophistication of their cyber operations.
undercodenews.com
October 21, 2025 at 8:05 PM
Russia’s COLDRIVER Unleashes New Wave of Cyber Weapons: NOROBOT, YESROBOT, and MAYBEROBOT

The Hidden Cyber War Intensifies In the quiet hours of global networks, a silent battlefield is taking shape. Russian state-sponsored hacking group COLDRIVER, also known as Star Blizzard, has resurfaced with…
Russia’s COLDRIVER Unleashes New Wave of Cyber Weapons: NOROBOT, YESROBOT, and MAYBEROBOT
The Hidden Cyber War Intensifies In the quiet hours of global networks, a silent battlefield is taking shape. Russian state-sponsored hacking group COLDRIVER, also known as Star Blizzard, has resurfaced with a new and more sophisticated arsenal of malware — a clear escalation in the ongoing digital cold war. The group, long associated with cyber espionage against Western institutions, has reportedly replaced its previous malware suite “LOSTKEYS” with three new tools: NOROBOT, YESROBOT, and MAYBEROBOT.
undercodenews.com
October 21, 2025 at 8:07 AM
Feed: "The Hacker News"
By: info@thehackernews.com (The Hacker News) on Tuesday, October 21, 2025
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 10:08 PM
Google's Threat Intelligence Group uncovers three new Russian malware families NOROBOT, YESROBOT, and MAYBEROBOT developed by COLDRIVER hackers. #CyberSecurity #COLDRIVER #MalwareAlert Link: thedailytechfeed.com/google-uncov...
October 22, 2025 at 10:13 AM
Google、COLDRIVERハッカーが作成した3つの新しいロシアのマルウェアファミリーを特定

COLDRIVERとして知られるロシア関連のハッキンググループに起因する新しいマルウェアは、2025年5月以来、何度も開発が繰り返されており、脅威アクターによる「活動ペース」が加速していることを示唆している。

この調査結果はGoogle Threat Intelligence Group(GTIG)によるもので、同グループによると、国家が支援するハッカー集団は、同時期にLOSTKEYSマルウェアが公開されてからわずか5日後に、マルウェアの武器庫を急速に改良し、再編成したという。
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
November 17, 2025 at 2:11 PM
Russia-linked COLDRIVER rapidly evolved multiple malware families (NOROBOT, YESROBOT, MAYBEROBOT) and changed tactics to deploy credential- and info-stealing malware via ClickFix lures.
Save What Matters
Curate Feeds | Make Collections | Customize Email Briefs
briefly.co
October 21, 2025 at 7:51 AM
「私はロボットではありません」:ロシアのハッカーが偽CAPTCHAを使いスパイツールを配布

研究者は、グループの迅速な戦術転換とターゲットの絞り込みが検知を複雑にし、行動ベースの防御が必要だと警告している。 Google Cloudの脅威インテリジェンスグループ(GTIG)によると、ロシア政府支援のハッカーが偽の「私はロボットではありません」CAPTCHAページを使い、新種のスパイマルウェアを配布している。これは、長年西側政府やシンクタンク、メディア組織を標的としてきたColdRiverグループによる戦術の新たな進化を示している。 このグループは、Star…
「私はロボットではありません」:ロシアのハッカーが偽CAPTCHAを使いスパイツールを配布
研究者は、グループの迅速な戦術転換とターゲットの絞り込みが検知を複雑にし、行動ベースの防御が必要だと警告している。 Google Cloudの脅威インテリジェンスグループ(GTIG)によると、ロシア政府支援のハッカーが偽の「私はロボットではありません」CAPTCHAページを使い、新種のスパイマルウェアを配布している。これは、長年西側政府やシンクタンク、メディア組織を標的としてきたColdRiverグループによる戦術の新たな進化を示している。 このグループは、Star Blizzard、UNC4057、Callistoとも呼ばれ、以前露呈したLostKeysマルウェアを、新たなツール群(NOROBOT、YESROBOT、MAYBEROBOT)に置き換えている。 これらのプログラムは、多段階の配布チェーンや暗号化されたペイロードを用いることで検知を回避できる。Googleによれば、この転換は今年初めに同社がLostKeysの技術的詳細を公開した数日後に起きたという。 ColdRiverの最新キャンペーンは、「ClickFix」と呼ばれるソーシャルエンジニアリング手法を使い、被害者にCAPTCHA認証手順を装った悪意のあるコードを実行させるよう仕向けている。 「NOROBOTおよびその前段階の感染チェーンは絶えず進化しており、最初は展開成功率を高めるため簡略化され、その後は暗号鍵を分割することで複雑さを再導入した」とGTIGは述べている。「より複雑な配布チェーンへの回帰は、キャンペーンの追跡を困難にしている。この絶え間ない開発は、高価値標的に対する情報収集を継続するため、配布メカニズムの検知回避に努めていることを示している。」 この手法は、国家支援型の作戦において、心理的操作とステルス性の高いモジュール型マルウェアを組み合わせて企業防御を回避する傾向が強まっていることを示している。 「ColdRiverが露呈したインフラから偽CAPTCHAのような新たな配布手法へ迅速に切り替えたことは、彼らの能力の高さを示している」とAkshat Tyagi(HFS Researchアソシエイトプラクティスリーダー)は述べた。「彼らは運用面で非常に機敏で、実質的に数週間でインフラを切り替え、配布メカニズムを書き換え、新たなペイロードを展開した。資金やリソースも豊富なチームのようだ。モジュール型アーキテクチャを持ち、コンポーネントの差し替えが可能で、グローバルなエンジニアリング人材にもアクセスしているのだろう。」 調査結果の詳細 Googleによれば、新たなマルウェアファミリーは2025年5月から9月にかけて活発に開発されており、攻撃者は検知回避のためツールを繰り返し改良している。アップデートの速さは、ColdRiverが公に露呈した直後でも即座にツールセットを再構築できる能力を示している。 最初期のNOROBOTサンプルは、復号鍵を複数のコンポーネントに分割し、特定の順序で再結合しないと最終ペイロードを復号できない暗号方式を用いていた。 YESROBOTはGoogleのレポートによると、すべてのコマンドが有効なPythonである必要がある最小限のPythonバックドアであり、ファイルのダウンロードやドキュメント取得といった基本機能の実装が煩雑になるという。後期のNOROBOTビルドは大幅に簡略化され、観測されたケースでは1つのファイルを取得し、ログオンスクリプトをインストールして永続化を確立した。 「NOROBOTのバリアント間で行われた具体的な変更は、高価値標的に対する情報収集を継続しつつ、検知システムを回避しようとするグループの執拗な努力を浮き彫りにしている」とレポートは述べている。 進化する戦術と戦略 アナリストによれば、ColdRiverは長年認証情報の窃取やメールアカウント侵害に注力してきたが、現在はユーザーに悪意のあるコードを実行させる多段階侵入へとシフトしている。 CAPTCHA認証画面を模倣したClickFixページを使うことで、グループはメールのセキュリティフィルターを回避し、マルウェアを被害者のデバイスに直接配布でき、感染の可能性を高めている。 「この段階では、エンドユーザーが偽のCAPTCHAを見抜いて排除することは難しい。CAPTCHAは標準的なアクセスプロセスの一部だからだ」とサイバーセキュリティアナリストのSunil Varkeyは述べた。「唯一の選択肢は、EDRやNDRなどのツールを使って行動変化やLiving-off-the-landテレメトリ、異常な活動を監視することだ。組織は特定のシナリオでユーザーやホストがどう振る舞うかを理解し、逸脱を監視する必要がある。そのためには強固なベースラインを持ち、それを徹底することが求められる。」 単純なフィッシングから多段階・双方向型攻撃への転換は、ColdRiverがユーザーのサイバー意識向上に適応していることを示している。従来の誘導手法は疑わしいリンクを警戒する人が増えたため効果が薄れているが、CAPTCHAページは依然として親しみやすく安全に感じられ、その信頼をColdRiverは悪用している。 「戦術的には、ColdRiverが運用セキュリティ(OPSEC)とステルス性に注力していることを示している」とSanjaya Kumar(SureShield CEO)は述べた。「マルウェアは暗号化通信や解析回避技術を使い、数か月間検知されずに長期アクセスを維持する。標的は依然としてNGO、反体制派、政策アドバイザー、西側当局者など高価値だが、CAPTCHA手法はシンクタンクや学術界など、素早い認証情報窃取がスパイ活動につながるソフトターゲットにも拡大している。」 防御側にとっては、従来の二要素認証を超え、行動やコンテキストを考慮した監視でステルス性の高いユーザー支援型侵入を見抜く必要性を強調している。 企業向け防御策 攻撃者は特定の組織や個人を標的とするため、サーバーサイドフィルタリングを使って選ばれた被害者だけにマルウェアを配布でき、大規模な検知が困難になるとアナリストは指摘する。さらに、グローバルなセキュリティベンダーが新たな攻撃に対するシグネチャをまだ開発・優先していない場合、検知はさらに難しくなる。 「防御側は、これは市販のマルウェアを使う単純なフィッシング集団ではないことを十分認識すべきだ」とVarkeyは述べた。「国家と関係がある、あるいは国家が支援するグループで、豊富なリソースと新たなツールや配布手法への迅速な切り替え能力を持っている。防御側はIOC(インジケーター・オブ・コンプロマイズ)だけに頼ることはできず、組織は高価値資産を守るためにセキュリティ体制を大幅に強化する必要があるかもしれない。」 Kumarはさらに、効果的な防御には、異常なPowerShell実行やコマンド&コントロールサーバーへの不審なネットワークコール、ファイルレスマルウェアのパターンなどを監視するツールを使った多層的かつ行動重視のアプローチが必要だと述べた。 セキュリティチームは通常の活動のベースラインを確立し、海外IPからの予期しないログイン試行や急速なデータ流出など逸脱があればアラートを出すべきだ。「ゼロトラストアーキテクチャの構築に注力し、最小権限アクセスやマイクロセグメンテーションを徹底して横展開を制限すべきだ」とKumarは述べた。「エンドポイントが悪用される前にパッチを適用する継続的な脆弱性管理、インタラクティブなフィッシング(例:CAPTCHA攻撃の模擬訓練)に関するセキュリティ意識向上トレーニングで成功率を下げること。インシデントレスポンスも強化し、多段階攻撃を模擬して封じ込めをテストする。積極的なサイバーハイジーン(定期的なパッチ適用、エンドポイント強化、脅威ハンティング)が不可欠だ。」 翻訳元:
blackhatnews.tokyo
October 22, 2025 at 12:07 PM
ロシアのハッカー、「私はロボットではありません」キャプチャで配布されるマルウェアを進化

ロシア政府支援のハッカーグループ「Star Blizzard」は、ClickFixによるソーシャルエンジニアリング攻撃から始まる複雑な配布チェーンで、新たに絶えず進化するマルウェアファミリー(NoRobot、MaybeRobot)を展開し、活動を強化しています。 ColdRiver、UNC4057、Callistoとしても知られるStar…
ロシアのハッカー、「私はロボットではありません」キャプチャで配布されるマルウェアを進化
ロシア政府支援のハッカーグループ「Star Blizzard」は、ClickFixによるソーシャルエンジニアリング攻撃から始まる複雑な配布チェーンで、新たに絶えず進化するマルウェアファミリー(NoRobot、MaybeRobot)を展開し、活動を強化しています。 ColdRiver、UNC4057、Callistoとしても知られるStar Blizzard脅威グループは、研究者が分析結果を公開してから1週間も経たないうちにLostKeysマルウェアを放棄し、*Robot系の悪意あるツールをこれまでのキャンペーンよりも「より積極的に」活用しました。 5月のレポートで、Google Threat Intelligence Group(GTIG)は、 このマルウェアが諜報目的で使用されており、ハードコードされた拡張子やディレクトリのリストに基づくデータの持ち出し機能を持っていると述べています。 LostKeysマルウェアを公開した後、GTIGの研究者は、ColdRiverが完全にこれを放棄し、5日後にはNOROBOT、YESROBOT、MAYBEROBOTとして追跡される新たな悪意あるツールを展開し始めたと述べています。 GTIGによると、再編成はNOROBOTから始まりました。これは「ClickFix」攻撃を通じて配布される悪意あるDLLで、偽のCAPTCHAページを使ってターゲットを騙し、検証プロセスを装ってrundll32経由で実行させるものでした。 ハッカーは、ターゲットに「私はロボットではありません」というキャプチャチャレンジを実行させ、人間であることを証明させるために、NOROBOTマルウェアを起動するコマンドを実行させようとします。 NOROBOT配布に使われたClickFixページ出典: Google クラウドセキュリティ企業Zscalerの研究者は9月にNOROBOTを分析し、BAITSWITCHと命名し、そのペイロードであるバックドアをSIMPLEFIXと呼びました。 GoogleはNOROBOTが5月から9月にかけて継続的に開発されてきたと述べています。 NOROBOTはレジストリの変更やスケジュールタスクによって永続化を獲得し、最初はYESROBOTというPythonベースのバックドア用にWindows向けのPython 3.8フルインストールを取得していました。 しかし、GTIGは、YESROBOTの使用期間は短かったと指摘しています。Pythonのインストールが明らかな痕跡となり注目を集めるため、ColdRiverはこれを放棄し、別のバックドアであるPowerShellスクリプトのMAYBEROBOT(ZscalerによってSIMPLEFIXと識別)に切り替えました。 6月初旬以降、「大幅に単純化された」バージョンのNOROBOTがMAYBEROBOTを配布し始めました。MAYBEROBOTは以下の3つのコマンドをサポートします: 指定されたURLからペイロードをダウンロードして実行 コマンドプロンプト経由でコマンドを実行 任意のPowerShellブロックを実行 実行後、MAYBEROBOTは結果を個別のコマンド&コントロール(C2)パスに返し、Coldriverに作戦の成功状況をフィードバックします。 Coldriverの現在の攻撃チェーン出典: Google Googleのアナリストは、MAYBEROBOTの開発は安定してきており、脅威アクターは現在、NOROBOTをよりステルス性が高く効果的にすることに注力しているとコメントしています。 研究者は、複雑な配布チェーンから単純なもの、そして再び複雑なものへと変化し、暗号鍵を複数のコンポーネントに分割する手法に移行したことに気付きました。最終的なペイロードの復号には、これらのパーツを正しく組み合わせる必要があると研究者は述べています。 「これは、おそらく感染チェーンの再構築を困難にするために行われたものであり、ダウンロードされたコンポーネントのいずれかが欠けていると、最終ペイロードは正しく復号されない」とGTIGはレポートで指摘しています。 ColdRiverによるNOROBOTおよびその後のペイロードをターゲットに配布する攻撃は、6月から9月の間に観測されています。 ColdRiverの活動はロシアの情報機関(FSB)に帰属されています。このグループは少なくとも2017年からサイバー諜報活動に従事しています。インフラの妨害[1, 2]、制裁、戦術の暴露などの妨害にもかかわらず、ColdRiverは依然として活動的かつ進化し続ける脅威です。 通常、この脅威グループはフィッシング攻撃でマルウェアを配布しますが、研究者はハッカーがClickFix攻撃に移行した理由をまだ特定できていません。 一つの説明としては、ColdRiverが以前フィッシングで侵害し、すでにメールや連絡先を盗んだターゲットに対して、NOROBOTやMAYBEROBOTのマルウェアファミリーを使用している可能性が考えられます。再度ターゲットにすることで、「デバイス上の情報から直接追加のインテリジェンス価値を得るため」だと研究者は推測しています。 Googleのレポートには、Robotマルウェア攻撃の検出に役立つ侵害の兆候(IoC)やYARAルールが掲載されています。 翻訳元:
blackhatnews.tokyo
October 21, 2025 at 3:20 PM
Google、COLDRIVERハッカーによって作成された3つの新しいロシア製マルウェアファミリーを特定

COLDRIVERとして知られるロシア関連のハッキンググループに起因する新たなマルウェアが、2025年5月以降、数多くの開発的改良を経ており、脅威アクターの「作戦ペース」が増加していることを示唆しています。 この調査結果はGoogle脅威インテリジェンスグループ(GTIG)によるもので、国家支援を受けたこのハッカー集団が、LOSTKEYSマルウェアの公開からわずか5日後に、自らのマルウェア兵器を急速に改良・再構築したと述べています。…
Google、COLDRIVERハッカーによって作成された3つの新しいロシア製マルウェアファミリーを特定
COLDRIVERとして知られるロシア関連のハッキンググループに起因する新たなマルウェアが、2025年5月以降、数多くの開発的改良を経ており、脅威アクターの「作戦ペース」が増加していることを示唆しています。 この調査結果はGoogle脅威インテリジェンスグループ(GTIG)によるもので、国家支援を受けたこのハッカー集団が、LOSTKEYSマルウェアの公開からわずか5日後に、自らのマルウェア兵器を急速に改良・再構築したと述べています。 新しいマルウェアファミリーがどれほど長く開発されていたかは現時点で不明ですが、テック大手の脅威インテリジェンスチームは、公開以降LOSTKEYSの単一のインスタンスも観測していないと述べています。 新たなマルウェアは、NOROBOT、YESROBOT、MAYBEROBOTというコードネームで呼ばれ、「配信チェーンを通じて接続された関連マルウェアファミリーの集合体」であると、GTIGの研究者ウェズリー・シールズ氏が月曜日の分析で述べています。 最新の攻撃の波は、COLDRIVERの典型的な手口、すなわちNGOの著名人、政策アドバイザー、反体制派を標的とした認証情報窃取とはやや異なります。対照的に、新たな活動は、ClickFixスタイルの誘導を利用して、偽のCAPTCHA認証プロンプトの一環としてWindowsの「ファイル名を指定して実行」ダイアログ経由で悪意のあるPowerShellコマンドを実行させることに焦点を当てています。 2025年1月、3月、4月に発見された攻撃は、LOSTKEYSとして知られる情報窃取マルウェアの展開につながりましたが、その後の侵入は「ROBOT」ファミリーのマルウェアの道を開きました。なお、NOROBOTとMAYBEROBOTのマルウェアファミリーは、それぞれZscaler ThreatLabzによってBAITSWITCHとSIMPLEFIXという名称で追跡されています。 新たな感染チェーンは、HTML ClickFix誘導であるCOLDCOPYから始まり、これはNOROBOTというDLLをドロップするよう設計されており、その後rundll32.exeを介して次の段階のマルウェアが実行されます。この攻撃の初期バージョンでは、YESROBOTというPython製バックドアが配布されていたとされ、その後脅威アクターはMAYBEROBOTというPowershellインプラントへと切り替えました。 YESROBOTは、ハードコードされたコマンド&コントロール(C2)サーバーからHTTPS経由でコマンドを取得します。最小限のバックドアであり、ファイルのダウンロードと実行、関心のあるドキュメントの取得が可能です。YESROBOTの展開が観測されたのはこれまでに2件のみで、いずれもLOSTKEYSの詳細が公になった直後の5月下旬の2週間に集中しています。 対照的に、MAYBEROBOTはより柔軟かつ拡張性が高いと評価されており、指定されたURLからペイロードをダウンロード・実行したり、cmd.exeを使ってコマンドを実行したり、PowerShellコードを実行する機能を備えています。 COLDRIVERのアクターは、YESROBOTを「つなぎの仕組み」として急いで展開したと考えられており、これは公表への対応だった可能性が高いですが、その後MAYBEROBOTに切り替えられました。というのも、NOROBOTの最初期バージョンには、侵害されたホストに完全なPython 3.8をダウンロードするステップが含まれており、これは「目立つ」痕跡であり疑念を招くからです。 Googleはまた、NOROBOTおよびMAYBEROBOTの使用は、既にフィッシングなどで侵害されている可能性のある重要な標的に限定されている可能性が高く、最終的な目的はそのデバイスから追加の情報を収集することだと指摘しています。 「NOROBOTとその前段階の感染チェーンは絶えず進化してきました――当初は展開成功率を高めるために単純化され、その後暗号鍵を分割することで複雑さが再導入されました」とシールズ氏は述べています。「この絶え間ない開発は、グループが高価値標的に対する継続的な情報収集のために、配信メカニズムの検知回避を目指していることを浮き彫りにしています。」 この発表は、オランダの検察庁(Openbaar Ministerie、OM)が、3人の17歳の男性が外国政府にサービスを提供した疑いで捜査されていると発表した中で行われました。そのうちの1人はロシア政府系のハッカーグループと接触していたとされています。 「この容疑者は他の2人に対し、ハーグで複数回にわたりWi-Fiネットワークの調査を指示しました」とOMは述べています。「収集された情報は、元容疑者によって報酬と引き換えに依頼主に共有され、デジタルスパイ活動やサイバー攻撃に利用される可能性があります。」 容疑者のうち2人は2025年9月22日に拘束され、もう1人は当局による聴取も受けましたが、「事件における限定的な役割」のため自宅軟禁下に置かれています。 「ロシア政府系ハッカーグループと接触していた容疑者に対して、圧力がかけられた形跡はまだありません」とオランダ政府機関は付け加えています。 翻訳元:
blackhatnews.tokyo
October 21, 2025 at 7:40 AM
Google attribuisce a COLDRIVER un nuovo malware russo con famiglie NOROBOT e MAYBEROBOT, evoluto per eludere rilevamenti e condurre operazioni di spionaggio.

#apt #backdoor #coldriver #GoogleThreatIntelligenceGroup #MAYBEROBOT #NOROBOT #Russia #YESROBOT
www.matricedigitale.it/2025/10/20/n...
October 20, 2025 at 8:17 PM
"This suspect also gave the other two instructions to map Wi-Fi networks on multiple dates in The Hague," OM said. "The information collected has been shared with the client by the former suspect for a fee and can be used for digital espionage and cyber attacks."
thehackernews.com/2025/10/goog...
October 21, 2025 at 11:38 PM
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers

#thehackersnews
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 10:30 AM