#coldriver
Coldriver (fore) and Riptide (behind) for StarCanid and RN-Roadster on ArtFight, respectively.

I'm in an especially potent dinosaur mood tonight 🦖

#pixelzart #pathoftitans #sharemyattack2026
July 3, 2026 at 1:32 AM
I wrote some details on LOSTKEYS: malware which we directly attribute to COLDRIVER. They don't deploy it often, but we have seen it a few times and want to make people aware of it.

cloud.google.com/blog/topics/...
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
cloud.google.com
May 7, 2025 at 2:14 PM
cloud.google.com/blog/topics/...

I wrote some more on COLDRIVER - specifically about their recent malware they have been using since at least May. If you’re on the COLDRIVER target list keep an eye out for this stuff. They have been more active with it than previous malware.
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog
Russia state-sponsored COLDRIVER started using new malware immediately following a May public disclosure of their activity.
cloud.google.com
October 20, 2025 at 3:19 PM
www.zscaler.com/blogs/securi... - Nice writeup by zscaler on some COLDRIVER malware. I'm talking about this stuff at #FTSCon in a few weeks and will have lots more details there.
COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz
The Russia-linked group COLDRIVER targeted dissidents and their supporters using a ClickFix technique, resulting in the deployment of BAITSWITCH and SIMPLEFIX.
www.zscaler.com
September 26, 2025 at 2:45 PM
Russian state-linked Coldriver spies add new malware to operation

therecord.media/coldriver-ru...
Russian state-linked Coldriver spies add new malware to operation
A Russian cyber-espionage group tracked as Coldriver by Google researchers has updated its malware toolset.
therecord.media
May 9, 2025 at 9:44 AM
Sunnier days last summer had me sitting by the Cold River in the Berkshires. It runs alongside a mountainous section of the of the Mohawk Trail

#scape #ForestFriday
#MohawkTrail #Berkshires #FloridaMA #ColdRiver #rocksandwater
#EastCoastKin #riverscape #PhotographersofBluesky #naturephotography
May 23, 2026 at 2:36 AM
Forgot to post these out here! My #Artfight attacks for this year! Had SO much fun with this year's attacks!

#Art #Creature #Anthro
August 21, 2025 at 5:06 PM
Dearlove has form. He's pro Brexit, pro Trump and a conspiracy theorist. Quite something for a former head of the Security Service www.computerweekly.com/news/2525253...
How Russian intelligence hacked the encrypted emails of former MI6 boss Richard Dearlove | Computer Weekly
Hack by Russian-linked ColdRiver group – aka Seaborgium, TA446 and Callisto – exposed former MI6 chief Richard Dearlove’s contacts and email communications with government, military, intelligence and ...
www.computerweekly.com
January 10, 2026 at 1:37 PM
Google linked the new LostKeys malware (used since January 2025) to the Russian state-backed ColdRiver (Star Blizzard) hacking group. Targeting governments, journalists, and NGOs via ClickFix attacks, ColdRiver also uses SPICA. A $10M reward is offered for information leading to their arrest.
May 9, 2025 at 4:04 AM
coldriver, coming in hot #apt ... with an army ranger lure? 762958cca94056412c01d8404d4c5e4ed602852bdbc052070e9c2ff44a3a5a5b
December 27, 2024 at 4:43 PM
This is fairly big. TA446 (aka COLDRIVER, Star Blizzard, Callisto) is a lower tier Russian APT group. They have now repurposed the recently leaked iOS exploit kit.
Proofpoint has directly observed a targeted email campaign that delivers DarkSword RCE, and we attribute the messages to Russian FSB threat actor TA446 with high confidence. 🧵
March 27, 2026 at 4:54 PM
Apparently my lightning talk at @cyberwarcon.bsky.social last year was released. Go watch it for a quick overview. COLDRIVER is still active, and still evolving to this day.

The critical question is do I want to use emojis when I post about them?
June 5, 2025 at 11:50 PM
COLDRIVER’s phishing isn’t new, but LOSTKEYS is.

Wesley Shields (Google TAG) just dropped new research on the FSB-linked threat group’s latest toolset.

Read the full blog:
cloud.google.com/blog/topics/...

Watch his CWC vid:
www.youtube.com/watch?v=gg5y...

#Cybersecurity #COLDRIVER
COLDRIVER Using New Malware To Steal Documents From Western Targets and NGOs | Google Cloud Blog
Russian government-backed group COLDRIVER is using LOSTKEYS malware to steal files and system information from NGOs and western targets.
cloud.google.com
May 28, 2025 at 3:39 PM
Since the start of the year, the Russian state-backed ColdRiver hacking group has been using new LostKeys malware to steal files in espionage attacks targeting Western governments, journalists, think tanks, and non-governmental organizations.
Google links new LostKeys data theft malware to Russian cyberspies
Since the start of the year, the Russian state-backed ColdRiver hacking group has been using new LostKeys malware to steal files in espionage attacks targeting Western governments, journalists, think tanks, and non-governmental organizations.
www.bleepingcomputer.com
May 8, 2025 at 1:39 PM
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
thehackernews.com
October 21, 2025 at 7:40 AM
🇷🇺 French NGO Reporters Without Borders targeted by #Calisto in recent campaign

Sekoia #TDR analysed a recent #Calisto (aka #ColdRiver #Star Blizzard) spear-phishing campaign aimed at Reporters sans frontières and other #Ukraine-supporting organisations.

blog.sekoia.io/ngo-reporter...
December 4, 2025 at 8:26 AM
Russia-linked ColdRiver used LostKeys malware in recent attacks
Russia-linked ColdRiver used LostKeys malware in recent attacks
Since early 2025, Russia-linked ColdRiver has used LostKeys malware to steal files in espionage attacks on Western governments and orgs.
securityaffairs.com
May 9, 2025 at 12:32 PM
I’m excited to announce that I’ll be co-writing the sequel to Fading Away: Dark Bay with Gaius Konstantine. While we’re busy making it happen — go read the first book. 📖

Get ebook and paperback here >>> tr.ee/VGcCWu

#bookstagram #booktok #FadingAwayDarkBay #ColdRiver
June 27, 2026 at 7:39 AM
#RPGaDay2026 Day 14: REGARD

Aeglos Coldriver was born a slave, one of many of his indigenous people conquered by invaders from across the sea (who were themselves fleeing from monstrous invaders of their own).
August 14, 2026 at 5:06 PM
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
September 18, 2025 at 4:29 PM
Not Iran...

Hack of Roger Stone's emails tracked back to "a group known as ColdRiver and other names. Multiple governments have said the group works for the FSB, Russia’s Federal Security Service, which operates worldwide"

🎁 article

wapo.st/3SMSzgO
Russian spy agency hackers breach human rights groups, victims say
Traditional phishing attacks aimed to break into organizations advocating for Russian dissidents, among others.
wapo.st
August 15, 2024 at 1:49 AM
3/ If you're already great at tricking people into giving you their credentials...

You'll be excellent at sliding them towards sites where you can host device exploits.

Do it at scale and you'll absolutely clean up.

Link: our @citizenlab.ca report on COLDRIVER

citizenlab.ca/research/sop...
Rivers of Phish: Sophisticated Phishing Targets Russia’s Perceived Enemies Around the Globe - The Citizen Lab
A sophisticated spear phishing campaign has been targeting Western and Russian civil society. In collaboration with Access Now, and with the participation of numerous civil society organizations, we u...
citizenlab.ca
March 27, 2026 at 6:06 PM
-Malware on Rust's Crates repo
-First malicious MCP server spotted
-New MIGA leak site
-New ShadowV2 DDoS botnet
-Russia uses pay-to-post scheme in Moldova info-ops
-COLDRIVER targets its own
-TAG-100 is now RedNovember
-Mandiant releases BRICKSTORM search tool
-How China trains its cyber forces
September 26, 2025 at 8:25 AM