Two spear-phishing campaigns targeted Russian and Belarusian civil society, independent media, and international NGOs, with COLDRIVER attributed to one campaign and an unnamed actor dubbed COLDWASTREL linked to another. The campaigns used highly personalized emails, compromised or lookalike accounts, and deceptive PDFs and login pages to harvest credentials and access sensitive information. #COLDRIVER #COLDWASTREL #AccessNow #CitizenLab #FirstDepartment #ProtonMail #ICANN #FSB #STARBLIZZARD #SEABORGIUM #CALLISTO
Keypoints
- Two spear-phishing campaigns targeted civil society organizations in Eastern Europe, including Russian/Belarusian groups and international NGOs.
- COLDRIVER is attributed to a Russia-based threat group; the second campaign is attributed to an unnamed actor called COLDWASTREL.
- Phishing emails were highly personalized and often impersonated known contacts to increase credibility.
- Attackers used compromised accounts or lookalike email addresses to deceive victims.
- Phishing attempts included locked PDF attachments and links to fake login pages designed to harvest credentials.
- Successful attacks could grant unauthorized access to victim emails, risking exposure of sensitive information and potential legal repercussions.
MITRE Techniques
- [T1566] Phishing β Highly personalized emails targeting specific individuals or organizations; attackers used compromised accounts or lookalike emails and included malicious PDF attachments and links to fake login pages. βThe phishing attacks were highly tailored to show scenarios that the individuals or their organizations might feasibly encounter in their daily work, mentioning topics such as event planning or financial discussions.β
- [T1003] Credential Dumping β Harvesting user credentials through phishing attacks; βHarvesting user credentials through phishing attacks.β
Indicators of Compromise
- [Domain] impersonation β domains impersonating several prominent civil society organizations (example: domains impersonating CSOs)
- [IP] attacker-used IP β a specific IP address used by the attacker (not disclosed)
- [Email] compromised or lookalike accounts β compromised Proton Mail staff account; lookalike email addresses
- [Attachment] locked PDF attachments β seemingly locked PDFs designed to lure victims
- [URL] links to fake login pages β links within documents intended to harvest credentials
- [Credential] harvested credentials β credentials harvested via phishing leading to potential access
Read more: https://www.accessnow.org/russian-phishing-campaigns/