Menu
Intelliwings® Intelliwings® Intelliwings®
close
  • Home
  • About
  • Services & Tech
  • Team
  • Contact
  • Blog
  • Social Media
  • in
  • X
  • fb
  • ig
  • in
  • X
  • fb
  • ig
Cybersecurity Google Hackers Malware Microsoft Russia

Spica Uncovered: Google’s Response to Russian APT ColdRiver’s Latest Malware 

by Lauren LaPorta
January 23, 2024

| By Lauren LaPorta |

Russian advanced persistent threat (APT) ColdRiver has expanded and evolved its phishing campaigns against Western officials and allies of Ukraine through the deployment of a new custom backdoor, Spica. Google’s Threat Analysis Group (TAG) continues to protect user safety through Safe Browsing blocklists and user safety alerts. 

ColdRiver’s History of Cyber Espionage 

Google’s Threat Analysis Group has been reporting and fighting Russian APT ColdRiver espionage attempts since 2016 when it was first discovered by security researchers after its phishing campaign against Britain’s Foreign Office. ColdRiver, also known as Star Blizzard, Callisto, and UNC4057, is known for its espionage of high-profile individuals in NATO governments, NGOs, and former military and intelligence officers. Since the Russian invasion of Ukraine in 2022, ColdRiver has stepped up its phishing techniques to target Western allies of Ukraine. ColdRiver’s espionage efforts are known to be connected to the Russian government’s intelligence arm, the Federal Security Service. Google’s Threat Analysis Group (TAG) has been reporting and fighting this APT’s phishing campaigns aligned with the Russian government. In fact, research groups exposed ColdRiver campaigns and techniques last year, such as their campaign against three United States nuclear research labs: The Brookhaven, Argonne, and Lawrence Livermore National Laboratories. Consequently, ColdRiver has responded quickly by implementing new tactics, techniques, and procedures (TTPs). 

Advancing Threats: The Spica Backdoor 

ColdRiver’s phishing campaigns have evolved to include extended capabilities such as the use of custom backdoor malware. The APT continues credential phishing of Ukraine, NATO allies, academic institutions, and NGOs. ColdRiver employs impersonation accounts posing as an expert in a particular field connected to their target. The impersonation account sends a phishing link or document containing a link to their target, delivering malware through PDFs as lure documents. To trick users, ColdRiver impersonation accounts present these PDFs as a new op-ed or article that they wish to publish and seek feedback from their target. 

If the target opens the attached document, the text appears encrypted such that the user cannot read the document. If the target responds to the email that they are unable to read the document, the ColdRiver account responds with a link to a cloud storage site with a “decryption” tool the target can use. The decryption tool decodes the embedded PDF, writes it to disk, and displays the PDF as a decoy file for the user. Google’s TAG tracked this new custom malware as Spica, which gives ColdRiver direct access to their target’s device. Written in Rust and employing JSON for command and control, Spica supports a myriad of commands, such as stealing cookies from Chrome and Firefox. Google’s TAG first detected the use of Spica in September 2023, but TAG believes that ColdRiver’s use of Spica dates back to November 2022. While there are four different variants of PDF lures, TAG has only been able to retrieve one instance of Spica active around August and September of 2023. 

Cross-Regional Cyber Threats: Mint Sandstorm v. ColdRiver 

ColdRiver’s new custom backdoor mirrors Microsoft Threat Intelligence’s discovery of Mint Sandstorm, an Iranian APT that similarly deployed a new, custom backdoor called MediaPI and lured targets with Israel-Hamas War media. Similar to ColdRiver, Mint Sandstorm targets high-profile individuals in Middle Eastern affairs in academia and research in the United States, United Kingdom, Belgium, France, Gaza, and Israel. Mint Sandstorms’ espionage efforts are affiliated with the intelligence arm of Iran’s military, the Islamic Revolutionary Guard Corps (IRGC). Mint Sandstorms targets individuals with insights on policy and security issues that are of interest to Tehran. 

Google’s Measures to Protect User Safety 

Similar to Microsoft’s response to MediaPI, Google has taken initiatives to improve the safety and security of their users by adding all identified websites, domains, and files to Safe Browsing blocklists. Additionally, TAG continues to send targeted Gmail and Workspace users alerts of government-backed attackers to make them aware of the activity and encourage users to enable Enhanced Safe Browsing on Chrome and keep all devices up-to-date. Google and Microsoft’s ongoing efforts to counter cyber threats are crucial to continue to safeguard users’ sensitive information from the evolving landscape of government-backed cyber espionage. 

cybersecurity Google malware Russia
Like
Intelliwings Showcases Repy Boards® at AFWERX Expedient Basing Challenge Previous post Intelliwings Showcases Repy Boards® at AFWERX Expedient Basing Challenge
Microsoft Hacked by Russian State-Sponsored Group Next post Microsoft Hacked by Russian State-Sponsored Group
Recent Posts
  • Voices from Vietnam: Echoes of War at the Remnants Museum
  • Balancing Act: The Need for STEM and Humanities in Education
  • Qatar’s Media Empire: Al Jazeera and the Power of Narrative
  • China, Japan, and South Korea Meet In Trilateral Trade Dialogue
  • Devastating Earthquake Strikes Myanmar and Thailand
Archives
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • October 2020
  • January 2020
Recent Posts
  • Voices from Vietnam: Echoes of War at the Remnants Museum
  • Balancing Act: The Need for STEM and Humanities in Education
  • Qatar’s Media Empire: Al Jazeera and the Power of Narrative
  • China, Japan, and South Korea Meet In Trilateral Trade Dialogue
  • Devastating Earthquake Strikes Myanmar and Thailand
Archives
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • November 2022
  • October 2022
  • August 2022
  • July 2022
  • October 2020
  • January 2020
Intelliwings® Intelliwings® Intelliwings®
All images and content ©Intelliwings except for content attributed to other sources
Intelliwings is an SBA-Certified SDVOSB and Virginia State-Certified V3 Company
To top ↑
All images and content © Intelliwings from our global explorations and adventures, except content attributed to other sources. Please contact Intelliwings for any questions regarding our content.

Add comment

Comments

Cookies
To make this site work properly, we sometimes place small data files called cookies on your device. Most big websites do this too.
Accept
Read more
Cookie Box Settings

Privacy settings

Decide which cookies you want to allow.

You can change these settings at any time. However, this can result in some functions no longer being available. For information on deleting the cookies, please consult your browser’s help function.

Learn more about the cookies we use.

With the slider, you can enable or disable different types of cookies:

  • Block all
  • Essential
  • Functionality
  • Analytics
  • Advertising

This website will:

  • Essential: Remember your cookie permission setting
  • Essential: Allow session cookies
  • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
  • Essential: Keep track of what you input in shopping cart
  • Essential: Authenticate that you are logged into your user account
  • Essential: Remember language version you selected

This website won't:

  • Remember your login details
  • Functionality: Remember social media settings
  • Functionality: Remember selected region and country
  • Analytics: Keep track of your visited pages and interaction taken
  • Analytics: Keep track about your location and region based on your IP number
  • Analytics: Keep track on the time spent on each page
  • Analytics: Increase the data quality of the statistics functions
  • Advertising: Tailor information and advertising to your interests based on e.g. the content you have visited before. (Currently we do not use targeting or targeting cookies.
  • Advertising: Gather personally identifiable information such as name and location

This website will:

  • Essential: Remember your cookie permission setting
  • Essential: Allow session cookies
  • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
  • Essential: Keep track of what you input in shopping cart
  • Essential: Authenticate that you are logged into your user account
  • Essential: Remember language version you selected
  • Functionality: Remember social media settings
  • Functionality: Remember selected region and country

This website won't:

  • Remember your login details
  • Analytics: Keep track of your visited pages and interaction taken
  • Analytics: Keep track about your location and region based on your IP number
  • Analytics: Keep track on the time spent on each page
  • Analytics: Increase the data quality of the statistics functions
  • Advertising: Tailor information and advertising to your interests based on e.g. the content you have visited before. (Currently we do not use targeting or targeting cookies.
  • Advertising: Gather personally identifiable information such as name and location

This website will:

  • Essential: Remember your cookie permission setting
  • Essential: Allow session cookies
  • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
  • Essential: Keep track of what you input in shopping cart
  • Essential: Authenticate that you are logged into your user account
  • Essential: Remember language version you selected
  • Functionality: Remember social media settingsl Functionality: Remember selected region and country
  • Analytics: Keep track of your visited pages and interaction taken
  • Analytics: Keep track about your location and region based on your IP number
  • Analytics: Keep track on the time spent on each page
  • Analytics: Increase the data quality of the statistics functions

This website won't:

  • Remember your login details
  • Advertising: Use information for tailored advertising with third parties
  • Advertising: Allow you to connect to social sites
  • Advertising: Identify device you are using
  • Advertising: Gather personally identifiable information such as name and location

This website will:

  • Essential: Remember your cookie permission setting
  • Essential: Allow session cookies
  • Essential: Gather information you input into a contact forms, newsletter and other forms across all pages
  • Essential: Keep track of what you input in shopping cart
  • Essential: Authenticate that you are logged into your user account
  • Essential: Remember language version you selected
  • Functionality: Remember social media settingsl Functionality: Remember selected region and country
  • Analytics: Keep track of your visited pages and interaction taken
  • Analytics: Keep track about your location and region based on your IP number
  • Analytics: Keep track on the time spent on each page
  • Analytics: Increase the data quality of the statistics functions
  • Advertising: Use information for tailored advertising with third parties
  • Advertising: Allow you to connect to social sitesl Advertising: Identify device you are using
  • Advertising: Gather personally identifiable information such as name and location

This website won't:

  • Remember your login details
Save & Close