Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware
Russian COLDRIVER Hackers Expand Beyond Phishing with Custom Malware
18 January 2024
The Russia-linked threat actor known as COLDRIVER has been observed evolving its tradecraft to go beyond credential harvesting to deliver its first-ever custom malware written in the Rust programming language.
Google's Threat Analysis Group (TAG), which shared details of the latest activity, said the attack chains leverage PDFs as decoy documents to trigger the infection sequence. The lures are