Odisha News, Odisha Latest news, Odisha Daily - OrissaPOST
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
No Result
View All Result
OrissaPOST - Odisha Latest news, English Daily -
No Result
View All Result

Russian threat group delivering malware via campaigns using PDFs: Google

IANS
Updated: January 19th, 2024, 14:38 IST
in Sci-Tech
0
Malware

Representational pic

Share on FacebookShare on TwitterShare on WhatsAppShare on Linkedin

New Delhi: Google researchers have observed that the notorious Russian threat group — COLDRIVER, focused on credential phishing activities, has now gone beyond it by delivering “malware via campaigns using PDFs as lure documents”.

COLDRIVER, also known as ‘UNC4057’, ‘Star Blizzard’ and ‘Callisto’ has focused on credential phishing against Ukraine, NATO countries, academic institutions and NGOs.

Also Read

Drones

Ukraine offers drone defence tech as geopolitical bargaining tool

2 weeks ago

Andhra Pradesh to ban social media for children under 13 in 90 days

2 weeks ago

In order to gain the trust of targets, the group often utilises impersonation accounts, pretending to be an expert in a particular field or somehow affiliated with the target.

According to new research by Google’s Threat Analysis Group (TAG), COLDRIVER has increased its activity in recent months and is now using new tactics that can cause more disruption to its victims.

“As far back as November 2022, TAG has observed COLDRIVER sending targets benign PDF documents from impersonation accounts,” Google said in a blogpost Thursday.

The threat group presents these documents as a new op-ed or other type of article that the impersonation account is looking to publish, asking for feedback from the target. When the user opens the benign PDF, the text appears encrypted, the researchers explained.

If the target responds that they cannot read the encrypted document, the COLDRIVER impersonation account responds with a link, usually hosted on a cloud storage site, to a “decryption” utility for the target to use.

“This decryption utility, while also displaying a decoy document, is in fact a backdoor, tracked as SPICA, giving COLDRIVER access to the victim’s machine,” the researchers said.

In 2015 and 2016, TAG observed COLDRIVER using the Scout implant that was leaked during the Hacking Team incident of July 2015.

SPICA represents the first custom malware that the TAG researchers attribute to being developed and used by COLDRIVER.

The researchers have observed SPICA being used as early as September 2023, but believe that COLDRIVER’s use of the backdoor goes back to at least November 2022.

IANS

Tags: GoogleMalwareRussia
ShareTweetSendShare
Suggest A Correction

Enter your email to get our daily news in your inbox.

 

OrissaPOST epaper Sunday POST OrissaPOST epaper

Click Here: Plastic Free Odisha

#MyPaperBagChallenge

Anup Mahapatra

December 12, 2019
#MyPaperBagChallenge

Aishwarya Ranjan Mohanty

December 12, 2019
#MyPaperBagChallenge

Geetanjali Patro

December 12, 2019
#MyPaperBagChallenge

Rajashree Pravati Mohanty

December 12, 2019
#MyPaperBagChallenge

Bijswajit Pradhan

December 12, 2019
#MyPaperBagChallenge

Parbati Mohanty

December 12, 2019
#MyPaperBagChallenge

Sibarama Khotei

December 12, 2019
#MyPaperBagChallenge

Akshaya Kumar Dash

December 12, 2019
?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
#MyPaperBagChallenge

Dibya Ranjan Das

December 12, 2019
#MyPaperBagChallenge

Subhajyoti Mohanty

December 12, 2019
#MyPaperBagChallenge

Pitabas Tripathy

December 12, 2019
#MyPaperBagChallenge

Jyotshna Mayee Pattnaik

December 12, 2019
#MyPaperBagChallenge

Anasuya Sahoo

December 12, 2019
#MyPaperBagChallenge

Mandakini Dakua

December 12, 2019
#MyPaperBagChallenge

Anshuman Sahoo

December 12, 2019
#MyPaperBagChallenge

Priyasha Pradhan

December 12, 2019
#MyPaperBagChallenge

Ramakanta Sahoo

December 12, 2019
#MyPaperBagChallenge

Spinoj Pattnaik

December 12, 2019
#MyPaperBagChallenge

Sipra Mishra

December 12, 2019
#MyPaperBagChallenge

Praptimayee Biswal

December 12, 2019
#MyPaperBagChallenge

Ipsita

December 12, 2019
#MyPaperBagChallenge

Adweeti Bhattacharya

December 12, 2019
#MyPaperBagChallenge

Tapaswini Mallick

December 12, 2019
#MyPaperBagChallenge

Akriti Negi

December 12, 2019
#MyPaperBagChallenge

Adyasha Priyadarsani Sendha

December 12, 2019
#MyPaperBagChallenge

Tabish Maaz

December 12, 2019
#MyPaperBagChallenge

Archana Parida

December 12, 2019
#MyPaperBagChallenge

Debasis Mohanty

December 12, 2019
#MyPaperBagChallenge

Pratyasharani Ghibela

December 12, 2019
#MyPaperBagChallenge

Pratik Kumar Ghibela

December 12, 2019

Archives

Editorial

Ladakh Protests Again

Pic Credit: PTI
March 18, 2026

Protests by thousands of pro-democracy activists in Leh and Kargil districts on 16 March, demanding, among other things, statehood for...

Read moreDetails

Windfall For Russia

March 17, 2026

The ongoing war between the US-Israel combine and Iran has unexpectedly turned out to be a windfall for Russia. In...

Read moreDetails

Most Vulnerable

Crude oil
March 16, 2026

The widening conflict in West Asia is beginning to cast a shadow over India’s economic outlook. The country’s heavy dependence...

Read moreDetails

Diplomatic Drift

March 15, 2026

On 4 November 2013, then Prime Minister Manmohan Singh spoke to over 120 heads of Indian missions and outlined the...

Read moreDetails
  • Home
  • State
  • Metro
  • National
  • International
  • Business
  • Editorial
  • Opinion
  • Sports
  • About Us
  • Advertise
  • Contact Us
  • Jobs
Developed By Ratna Technology

© 2025 All rights Reserved by OrissaPOST

  • News in Odia
  • Orissa POST Epaper
  • Video
  • Home
  • Trending
  • Metro
  • State
  • Odisha Special
  • National
  • International
  • Sports
  • Business
  • Editorial
  • Entertainment
  • Horoscope
  • Careers
  • Feature
  • Today’s Pic
  • Opinion
  • Sci-Tech
  • About Us
  • Contact Us
  • Jobs

© 2025 All rights Reserved by OrissaPOST

    • News in Odia
    • Orissa POST Epaper
    • Video
    • Home
    • Trending
    • Metro
    • State
    • Odisha Special
    • National
    • International
    • Sports
    • Business
    • Editorial
    • Entertainment
    • Horoscope
    • Careers
    • Feature
    • Today’s Pic
    • Opinion
    • Sci-Tech
    • About Us
    • Contact Us
    • Jobs

    © 2025 All rights Reserved by OrissaPOST