Russian hackers shift to new malware tactics, Google says
Google researchers have issued a warning about a Russian hacker group that is using new tactics to trick its victims.
The company’s Threat Analysis Group (TAG) said the hacker group – known as Coldriver – is sending encrypted PDF files as a way to trick users into giving the group access to their devices. TAG says that for years, Coldriver has been focused on credential phishing against high profile individuals in NGOs, NATO governments and former intelligence and military officers.
In 2022, TAG claimed this group – sometimes referred to as Calisto – targeted a NATO Centre of Excellence and a number of eastern European militaries for the first time. The research group said Coldriver is continuing its credential phishing activities – often through impersonation activities. But the new tactic involves delivering malware directly to its victims.