#mayberobot
Star Blizzard's RedFlick needs one click to plant a Python backdoor via disguised scheduled tasks. https://intel.threadlinqs.com/threat/TL-2026-2787 #ThreatIntel #YESROBOT #NOROBOT #MAYBEROBOT
September 29, 2026 at 11:27 PM
#FTSCon Speaker Spotlight: Wesley Shields (@wxs.bsky.social) is presenting “COLDRIVER: NOROBOT/YESROBOT/MAYBEROBOT” in the HUNTER track.

See the full list of speakers + event info, including how to register, here: volatilityfoundation.org/from-the-sou...
September 18, 2025 at 4:29 PM
Too many kids getting wrapped up in groups like this. "three 17-year-old men have been suspected of providing services to a foreign government, with one of them alleged to be in contact with a hacker group affiliated with the Russian government." thehackernews.com/2025/10/goog...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 12:54 PM
Russian state-backed hackers Star Blizzard (aka #ColdRiver / Callisto / UNC4057) have ramped up ops, unleashing new malware — NOROBOT, YESROBOT, MAYBEROBOT — via ClickFix CAPTCHA-style lures. Victims think they’re proving they’re human — but end up running code. #CyberSecurity #APT
October 22, 2025 at 10:14 AM
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers thehackernews.com/2025/10/goog...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 22, 2025 at 4:12 PM
Russian hackers are spreading malware via fake CAPTCHA popups in a campaign called ClickFix. A browser extension steals logins, hijacks sessions & bypasses MFA. It’s stealthy, fast-evolving & hard to detect. Stay sharp.

bleepingcomputer.com/news/securit... #CyberSecurity #Malware #ClickFix
Russian hackers evolve malware pushed in "I am not a robot" captchas
The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with…
bleepingcomputer.com
October 22, 2025 at 7:01 PM
COLDRIVER re-tooled within days of LOSTKEYS - a fake CAPTCHA now drops its NOROBOT ClickFix chain. https://intel.threadlinqs.com/threat/TL-2026-1510 #ThreatIntel #NOROBOT #YESROBOT #MAYBEROBOT
July 19, 2026 at 7:17 AM
Notícia da BleepingComputer

"Russian hackers evolve malware pushed in "I am not a robot" captchas" #bolhasec
Russian hackers evolve malware pushed in "I am not a robot" captchas
The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with Cl...
www.bleepingcomputer.com
October 28, 2025 at 6:30 PM
📰 Peretas Rusia Gunakan Malware Baru di CAPTCHA "I Am Not a Robot"

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2025/10/22/russian-hackers-norobot-malware-captcha/

#cli
ck#clickfixr#coldrivero#espionagel#googlea#malwaree#mayberobotb#noroboti#russia #starz#blizzard
October 22, 2025 at 7:08 AM
Google alerta sobre 3 novas ameaças cibernética criada por hackers russos
O Grupo de Inteligência de Ameaças do Google (GTIG) identificou uma nova e acelerada onda de desenvolvimento de malwares atribuída ao COLDRIVER — um grupo de hackers associado ao governo russo. A descoberta foi detalhada em uma publicação feita nesta segunda-feira (20), revelando o surgimento de três novas ameaças cibernéticas: NOROBOT, YESROBOT e MAYBEROBOT. De acordo com o Google, a **nova família de malwares passou por “múltiplas iterações” desde maio deste ano** , o que demonstra um ritmo acelerado de evolução e operação por parte do COLDRIVER. As variantes descobertas compartilham uma cadeia de distribuição interligada, sugerindo um esforço coordenado de aprimoramento técnico e escalabilidade. A instalação do malware acontece por meio do método ClickFix. (Fonte: Google/Reprodução) Tradicionalmente conhecido por empregar ataques de phishing para comprometer alvos e roubar dados sensíveis, o COLDRIVER parece agora expandir seu escopo. “Está claro que eles investiram esforços significativos em seu desenvolvimento para reequipar e implantar seu malware em alvos específicos”, afirmou o GTIG. O **grupo acredita que os novos malwares sejam usados para infectar vítimas previamente comprometidas** , cujos dados e contatos foram extraídos em campanhas anteriores. O COLDRIVER — **também identificado pelos nomes UNC4057, Star Blizzard e Callisto** — é patrocinado pelo Estado russo e costuma mirar indivíduos de alto perfil, como consultores políticos, dissidentes e integrantes de ONGs. O avanço observado nos últimos meses coincide com a descoberta do malware LOSTKEYS, revelado em maio, o que reforça a hipótese de uma nova fase de atuação do grupo. ## Como acontece a infecção? A infecção ocorre a partir de um anúncio falso chamado ClickFix, disfarçado sob o nome COLDCOPY. Ao clicar no aviso, o usuário inicia o download do malware NOROBOT, executado por meio do processo legítimo `rundll32.exe`. Esse arquivo, por sua vez, aciona o próximo estágio da cadeia de ataque. Em versões iniciais, o NOROBOT distribuía o backdoor YESROBOT. Nas iterações mais recentes, no entanto, o COLDRIVER substituiu o payload pelo MAYBEROBOT — uma versão mais avançada e versátil, capaz de baixar cargas a partir de URLs específicos, executar comandos via CMD e rodar códigos diretamente no PowerShell. Os **malwares NOROBOT e MAYBEROBOT também são monitorados pela empresa de cibersegurança Zscaler** **ThreatLabz** , mas com os nomes BAITSWITCH e SIMPLESFIX, respectivamente. ## Google alertou vítimas sobre a atividade irregular O Google segue monitorando a evolução da família de malwares, destacando a rapidez com que o COLDRIVER adaptou e expandiu suas ferramentas ofensivas em poucos meses. Como medida de contenção, todas as páginas, os domínios e os arquivos maliciosos encontrados durante a investigação foram adicionados à lista de restrição do Safe Browsing. Alvos antigos e potenciais vítimas também foram alertados. Quer saber mais sobre cibersegurança e ameaças digitais? Acompanhe o **TecMundo** para se manter atualizado sobre as mais recentes descobertas, vulnerabilidades e estratégias de proteção no mundo da tecnologia.
www.tecmundo.com.br
October 21, 2025 at 7:56 PM
macOS ClickFix spreads Infiniti Stealer via Nuitka loader; TA446 exploits iOS with DarkSword deploying GHOSTBLADE, MAYBEROBOT; TeamPCP backdoors Telnyx PyPI using WAV steganography. EU cloud breach and FBI data leaks reported. #Infosec #iOSExploits
Cybersecurity News | Daily Recap [28 Mar 2026]
Daily Recap, a roundup of recent cybersecurity activity highlights macOS ClickFix delivering Infiniti Stealer via a Nuitka loader, iOS exploitation by TA446 using DarkSword to deploy GHOSTBLADE and MAYBEROBOT, and backdoored Telnyx PyPI packages pushed by TeamPCP that use WAV steganography to exfiltrate SSH keys and tokens. The report also covers critical advisories (CVE-2026-3055, CVE-2025-53521), the Open VSX Open Sesame fix, major breaches including the European Commission cloud incident and Handala's alleged exfiltration of FBI director materials, plus governance moves such as the CSAM ruling, UK donation limits, the Chip Security Act, and OpenAI's Bug Bounty program. #InfinitiStealer #DarkSword #GHOSTBLADE #MAYBEROBOT #TeamPCP #Telnyx #NetScaler #CVE2026-3055 #CVE2025-53521 #EuropeanCommission #AnimePlay #Handala #OpenAI #Bugcrowd #OpenVSX #CSAMRuling #ChipSecurityAct
www.hendryadrian.com
March 29, 2026 at 12:00 PM
Russia-linked TA446 used the leaked DarkSword iOS exploit kit in a spear-phishing campaign targeting iPhones and iPads. Spoofed Atlantic Council emails delivered GHOSTBLADE dataminer and MAYBEROBOT backdoor. #DarkSword #iOSAttack #Russia
TA446 Deploys DarkSword iOS Exploit Kit in Targeted Spear-Phishing Campaign
Proofpoint disclosed a targeted email campaign by Russia-linked TA446 that used the leaked DarkSword iOS exploit kit to target iPhones and iPads. The attacks spoofed the Atlantic Council, delivered the GHOSTBLADE dataminer and MAYBEROBOT backdoor, and prompted Apple to send Lock Screen warnings as DarkSword code leaked on GitHub. #TA446 #DarkSword...
www.hendryadrian.com
March 28, 2026 at 11:00 AM
🇷🇺 Russian APT COLDRIVER rapidly retooled after public disclosure, deploying new NOROBOT & MAYBEROBOT malware. The group is targeting NGOs & policy advisors with a new PowerShell backdoor. ⚡️ #COLDRIVER #APT #ThreatIntel #Russia
Russian APT COLDRIVER Rapidly Deploys New NOROBOT Malware After Public Disclosure
Russian APT group COLDRIVER (UNC4057) quickly deployed new malware families, NOROBOT and MAYBEROBOT, after its LOSTKEYS tool was publicly disclosed, targeting high-value individuals.
cyber.netsecops.io
October 24, 2025 at 1:33 AM
A new malware attributed to the Russia-linked hacking group known as COLDRIVER has undergone numerous developmental iterations since May 2025, suggesting an increased "operations tempo" from the threat actor. thehackernews.com/2025/10/go...
Google Identifies Three New Russian Malware Families Created by COLDRIVER Hackers
Google reveals COLDRIVER’s new malware families NOROBOT, YESROBOT, and MAYBEROBOT amid rising cyber espionage.
thehackernews.com
October 21, 2025 at 3:00 PM
Russian hackers evolve malware pushed in "I am not a robot" captchas

The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with ClickFix soc…

#hackernews #news
Russian hackers evolve malware pushed in "I am not a robot" captchas
The Russian state-backed Star Blizzard hacker group has ramped up operations with new, constantly evolving malware families (NoRobot, MaybeRobot) deployed in complex delivery chains that start with ClickFix social engineering attacks. [...]
www.bleepingcomputer.com
October 22, 2025 at 12:28 PM
Russia-Linked COLDRIVER Backdoor Evolves: From NOROBOT to MAYBEROBOT Targeting NGOs and Dissidents

In a chilling development in cyber espionage, Russia-linked hacking group COLDRIVER has advanced its malware capabilities, moving from its earlier NOROBOT backdoor to YESROBOT and now the latest…
Russia-Linked COLDRIVER Backdoor Evolves: From NOROBOT to MAYBEROBOT Targeting NGOs and Dissidents
In a chilling development in cyber espionage, Russia-linked hacking group COLDRIVER has advanced its malware capabilities, moving from its earlier NOROBOT backdoor to YESROBOT and now the latest variant, MAYBEROBOT. This evolution highlights a growing focus on NGOs, policy advisors, and dissident communities, marking a dangerous escalation in targeted cyber operations against civil society actors. Security analysts have traced multiple domains, IP addresses, and email-linked WHOIS records connected to these attacks, signaling a sophisticated infrastructure supporting the campaign.
undercodenews.com
November 26, 2025 at 10:20 PM
Russia-Linked Hacking Group COLDRIVER Escalates Malware Operations: Inside NOROBOT and MAYBEROBOT

Introduction Since May 2025, the Russia-linked cyberespionage group COLDRIVER has rapidly intensified its malware development, following the exposure of its LOSTKEYS malware. Known for targeting…
Russia-Linked Hacking Group COLDRIVER Escalates Malware Operations: Inside NOROBOT and MAYBEROBOT
Introduction Since May 2025, the Russia-linked cyberespionage group COLDRIVER has rapidly intensified its malware development, following the exposure of its LOSTKEYS malware. Known for targeting government officials, military personnel, journalists, and think tanks, COLDRIVER has been operating under aliases such as Seaborgium, UNC4057, Callisto, Star Blizzard, and TA446 since at least 2015. Recent intelligence from Google’s Threat Intelligence Group (GTIG) highlights a sharp acceleration in the group’s operational tempo and technical sophistication, signaling a new phase of aggressive cyberespionage activity.
undercodenews.com
October 22, 2025 at 6:43 AM
ColdRiver’s Rapid Malware Evolution: A New Era in Cyber Espionage

In a striking demonstration of adaptability and persistence, the Russian state-sponsored hacking group known as ColdRiver has swiftly evolved its malware arsenal following the public exposure of its previous tool, LOSTKEYS, in May…
ColdRiver’s Rapid Malware Evolution: A New Era in Cyber Espionage
In a striking demonstration of adaptability and persistence, the Russian state-sponsored hacking group known as ColdRiver has swiftly evolved its malware arsenal following the public exposure of its previous tool, LOSTKEYS, in May 2025. Within just five days of the disclosure, ColdRiver deployed a new suite of malware families—NOROBOT, YESROBOT, and MAYBEROBOT—marking a significant shift in their cyber espionage tactics. These developments underscore the group's commitment to maintaining operational continuity and enhancing the sophistication of their cyber operations.
undercodenews.com
October 21, 2025 at 8:05 PM
Russia’s COLDRIVER Unleashes New Wave of Cyber Weapons: NOROBOT, YESROBOT, and MAYBEROBOT

The Hidden Cyber War Intensifies In the quiet hours of global networks, a silent battlefield is taking shape. Russian state-sponsored hacking group COLDRIVER, also known as Star Blizzard, has resurfaced with…
Russia’s COLDRIVER Unleashes New Wave of Cyber Weapons: NOROBOT, YESROBOT, and MAYBEROBOT
The Hidden Cyber War Intensifies In the quiet hours of global networks, a silent battlefield is taking shape. Russian state-sponsored hacking group COLDRIVER, also known as Star Blizzard, has resurfaced with a new and more sophisticated arsenal of malware — a clear escalation in the ongoing digital cold war. The group, long associated with cyber espionage against Western institutions, has reportedly replaced its previous malware suite “LOSTKEYS” with three new tools: NOROBOT, YESROBOT, and MAYBEROBOT.
undercodenews.com
October 21, 2025 at 8:07 AM