Odisha News, Odisha Latest news, Odisha Daily - OrissaPOST
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
  • Home
  • Trending
  • State
  • Metro
  • National
  • International
  • Business
  • Feature
  • Entertainment
  • Sports
  • More..
    • Odisha Special
    • Editorial
    • Opinion
    • Careers
    • Sci-Tech
    • Timeout
    • Horoscope
    • Today’s Pic
  • Video
  • Epaper
  • News in Odia
No Result
View All Result
OrissaPOST - Odisha Latest news, English Daily -
No Result
View All Result

Russian threat group delivering malware via campaigns using PDFs: Google

IANS
Updated: January 19th, 2024, 14:38 IST
in Sci-Tech
0
Malware

Representational pic

Share on FacebookShare on TwitterShare on WhatsAppShare on Linkedin

New Delhi: Google researchers have observed that the notorious Russian threat group — COLDRIVER, focused on credential phishing activities, has now gone beyond it by delivering “malware via campaigns using PDFs as lure documents”.

COLDRIVER, also known as ‘UNC4057’, ‘Star Blizzard’ and ‘Callisto’ has focused on credential phishing against Ukraine, NATO countries, academic institutions and NGOs.

Also Read

Indian startup funding

Indian startups raise $184.75 million this week

2 days ago
Left to right: Tibor Kapu of Hungary, ISRO astronaut Shubhanshu Shukla of India, former NASA astronaut Peggy Whitson, and ESA astronaut Sławosz Uznański-Wiśniewski of Poland | SpaceX

India’s Shubhanshu Shukla gears up for space as Axiom-4 launch slated for June 19

3 days ago

In order to gain the trust of targets, the group often utilises impersonation accounts, pretending to be an expert in a particular field or somehow affiliated with the target.

According to new research by Google’s Threat Analysis Group (TAG), COLDRIVER has increased its activity in recent months and is now using new tactics that can cause more disruption to its victims.

“As far back as November 2022, TAG has observed COLDRIVER sending targets benign PDF documents from impersonation accounts,” Google said in a blogpost Thursday.

The threat group presents these documents as a new op-ed or other type of article that the impersonation account is looking to publish, asking for feedback from the target. When the user opens the benign PDF, the text appears encrypted, the researchers explained.

If the target responds that they cannot read the encrypted document, the COLDRIVER impersonation account responds with a link, usually hosted on a cloud storage site, to a “decryption” utility for the target to use.

“This decryption utility, while also displaying a decoy document, is in fact a backdoor, tracked as SPICA, giving COLDRIVER access to the victim’s machine,” the researchers said.

In 2015 and 2016, TAG observed COLDRIVER using the Scout implant that was leaked during the Hacking Team incident of July 2015.

SPICA represents the first custom malware that the TAG researchers attribute to being developed and used by COLDRIVER.

The researchers have observed SPICA being used as early as September 2023, but believe that COLDRIVER’s use of the backdoor goes back to at least November 2022.

IANS

Tags: GoogleMalwareRussia
ShareTweetSendShare
Suggest A Correction

Enter your email to get our daily news in your inbox.

 

OrissaPOST epaper Sunday POST OrissaPOST epaper

Click Here: Plastic Free Odisha

#MyPaperBagChallenge

Narendra Kumar

December 12, 2019
#MyPaperBagChallenge

Pratik Kumar Ghibela

December 12, 2019
#MyPaperBagChallenge

Anshuman Sahoo

December 12, 2019
#MyPaperBagChallenge

Mrutyunjaya Behera

December 12, 2019
#MyPaperBagChallenge

Adyasha Priyadarsani Sendha

December 12, 2019
#MyPaperBagChallenge

Manas Samanta

December 12, 2019
#MyPaperBagChallenge

Sarfraz Ahmad

December 12, 2019
#MyPaperBagChallenge

Pragyan Priyambada

December 12, 2019
#MyPaperBagChallenge

Geetanjali Patro

December 12, 2019
#MyPaperBagChallenge

Pratyasharani Ghibela

December 12, 2019
#MyPaperBagChallenge

Amritansh Mishra

December 12, 2019
#MyPaperBagChallenge

Archit Mohapatra

December 12, 2019
#MyPaperBagChallenge

Pratik Kumar

December 12, 2019
#MyPaperBagChallenge

Sisirkumar Maharana

December 12, 2019
#MyPaperBagChallenge

Adweeti Bhattacharya

December 12, 2019
#MyPaperBagChallenge

Priyabrata Mohanty

December 12, 2019
#MyPaperBagChallenge

Subhajyoti Mohanty

December 12, 2019
#MyPaperBagChallenge

Parbati Mohanty

December 12, 2019
#MyPaperBagChallenge

Adrita Bhattacharya

December 12, 2019
#MyPaperBagChallenge

Lopali Pattnaik

December 12, 2019
#MyPaperBagChallenge

Akshaya Kumar Dash

December 12, 2019
#MyPaperBagChallenge

Sibarama Khotei

December 12, 2019
#MyPaperBagChallenge

D Rama Rao

December 12, 2019
#MyPaperBagChallenge

Diptiranjan Biswal

December 12, 2019
#MyPaperBagChallenge

Sarmistha Nayak

December 12, 2019
#MyPaperBagChallenge

Archana Parida

December 12, 2019
#MyPaperBagChallenge

Ramakanta Sahoo

December 12, 2019
#MyPaperBagChallenge

Akriti Negi

December 12, 2019
#MyPaperBagChallenge

Debasis Mohanty

December 12, 2019
#MyPaperBagChallenge

Tapaswini Mallick

December 12, 2019

Archives

Editorial

Mid East Great Again

Iran's private message to Israel: ‘Can intervene if military campaign continues in Gaza’
June 16, 2025

For decades, current Israeli Prime Minister Benjamin Netanyahu has been warning about the “existential threat” that a nuclear-armed Iran poses...

Read more

Nameless Doctrine

June 15, 2025

On 12 June, the United Nations General Assembly adopted a resolution demanding an immediate, unconditional and lasting ceasefire in Gaza....

Read more

Graft in ED

June 14, 2025

When a senior Enforcement Directorate (ED) officer gets caught in a graft case, eyebrows go up. But when insiders start...

Read more

Clash of Titans

June 11, 2025

The world is watching with bated breath the fierce showdown between the richest man on earth Elon Musk and the...

Read more
  • Home
  • State
  • Metro
  • National
  • International
  • Business
  • Editorial
  • Opinion
  • Sports
  • About Us
  • Advertise
  • Contact Us
  • Jobs
Developed By Ratna Technology

© 2024 All rights Reserved by OrissaPOST

  • News in Odia
  • Orissa POST Epaper
  • Video
  • Home
  • Trending
  • Metro
  • State
  • Odisha Special
  • National
  • International
  • Sports
  • Business
  • Editorial
  • Entertainment
  • Horoscope
  • Careers
  • Feature
  • Today’s Pic
  • Opinion
  • Sci-Tech
  • About Us
  • Contact Us
  • Jobs

© 2024 All rights Reserved by OrissaPOST

    • News in Odia
    • Orissa POST Epaper
    • Video
    • Home
    • Trending
    • Metro
    • State
    • Odisha Special
    • National
    • International
    • Sports
    • Business
    • Editorial
    • Entertainment
    • Horoscope
    • Careers
    • Feature
    • Today’s Pic
    • Opinion
    • Sci-Tech
    • About Us
    • Contact Us
    • Jobs

    © 2024 All rights Reserved by OrissaPOST