COLDRIVER using new malware to steal from Western targets — Google
By: bitcoin ethereum news|2025/05/08 21:15:01
0
Share
Threat group COLDRIVER is using new malware to steal documents from Western targets, according to a May 7 report from Google Threat Intelligence. The malware, called LOSTKEYS, shows the evolution of the group from credential phishing to more sophisticated attacks. According to the Google report, the new malware is installed through four steps. The process involves a “lure website” with a fake CAPTCHA, a PowerShell script downloaded to the user’s clipboard, some device evasion, and retrieval of the final payload. Lastly, the malware is installed. LOSTKEYS is capable of stealing files from extensions and directories. It can also send system information and running processes back to COLDRIVER. The address from which the parts of the attack come is “165.227.148[.]68” according to Google. The company says it has already taken steps to mitigate any damage the LOSTKEYS malware will cause, including adding the malicious websites to the company’s “Safe Browsing” feature. According to Google, COLDRIVER is a Russian-backed threat group that typically engages in phishing attempts at high-profile Western targets, such as former diplomats, and journalists. In January 2024, it started an attack with a malware called “Spica,” which can execute arbitrary shell commands and download or upload software. Related: Crypto drainers now sold as easy-to-use malware at IT industry fairs Crypto hack losses hit all-time high in 2025 Crypto hacks have surged in 2025, with total losses reaching $2 billion in the first quarter alone — exceeding all losses recorded in 2024. According to a report by crypto cybersecurity firm Hacken, operational flaws and weak access controls remain key vulnerabilities — even among major centralized and decentralized players. Attackers are also increasingly using social engineering tactics to gain victims’ trust. Contributing to last quarter’s losses was the $1.5 billion hack of cryptocurrency exchange Bybit. The February attack was reportedly orchestrated by the Lazarus Group. Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis Source: https://cointelegraph.com/news/coldriver-new-malware-steal-western-targets-google?utm_source=rss_feed&utm_medium=feed&utm_campaign=rss_partner_inbound
You may also like

Morning News | Bitmine launches institutional Ethereum staking platform MAVAN; Franklin Templeton launches tokenized ETF; Morgan Stanley to issue and sponsor Bitcoin ETF
Overview of Important Market Events on March 25

Kalshi early employees: Whoever controls the traffic controls the market
Robinhood can decide where tens of millions of contracts go with the flip of a switch, while the exchanges do all the hard work but cannot control their own fate.

Tether signs contracts with four major audits, Circle's compliance moat collapses, stock price plummets by 20%
USDT, with a market value of 184 billion dollars, is undergoing its first comprehensive inspection in history.

Proudly Introducing Aethir Claw: Your AI Agent, Our Infrastructure
Explore Aethir Claw, an easy-to-deploy AI agent solution that offers fully isolated VPS, encrypted payments, and highly competitive pricing.

Why Buying Gold Can Lead to Bankruptcy
"There is no issue with 'buying gold,' the issue is 'buying whose gold.'"

If the US Treasury yield rises above 5%, will Bitcoin drop below $50,000?
During the US-Iran war, as the bond market exhibited a **"meltdown"** scenario, Bitcoin's upward momentum is showing signs of exhaustion.

Circle Plunges 20%: Crypto Earthquake Triggered by Draft Proposal
Compliance gave Circle both a suit of armor and a ball and chain.

After the Smoke Clears: 5 Possible Endings to the Middle East Conflict
The Crown Prince in Exile for Half a Century, Set to Return to Tehran?

Stablecoin Yields Discontinued, Circle Plunges 20% in One Day
Tightening Regulations and Increased Competition Lead Market to Reassess Stablecoin Business Models

AI Wired into War Machine | Rewire News Nightly
Anduril and Palantir are collaborating on the development of the core software for the Golden Dome anti-missile system, with a project budget of $18.5 billion.

Web3 is sick, but the cure is not AI
Encryption may have wasted too many years, and the current AI anxiety is merely a stress response of an industry that has overdrawn its narrative after facing external shocks.

Why must Web3 projects be included in RootData?
Behind the wave of exchanges delisting and the tightening of coin listing reviews, the "information transparency" of projects is becoming a key threshold that determines whether they can be seen and trusted.

Fluid Announces Updates on Resolv Hack Recovery and Compensation Plan
Key Takeaways Fluid has repaid approximately $70 million related to USR debts on the BNB and Plasma chains.…

Binance to Delist Key Spot Trading Pairs: What You Need to Know
Key Takeaways Binance is set to remove several spot trading pairs on March 27, 2026, at 11:00 AM…

Whale Activities in the Crypto Market: A Deep Dive into Recent Trends
Key Takeaways A significant whale deposit occurred 3 hours ago when 5.5 million USDT was moved to Binance…

Circle and Tether Freeze Iranian Exchange Wallex Wallet with $2.49M Assets on Hold
Key Takeaways Circle and Tether have frozen a significant amount of assets from an Iranian exchange called Wallex,…

James Wynn Engages in High-Leverage Bitcoin Short Position
Key Takeaways James Wynn recently opened a 40x leveraged short position on Bitcoin. His position involves 2.69 BTC,…

Major Whale Opens Significant 20x Leveraged Positions in ETH and BTC
Key Takeaways Whale 0x049b has executed large 20x leverage positions on 9,256 ETH and 282.47 BTC, totaling over…
Morning News | Bitmine launches institutional Ethereum staking platform MAVAN; Franklin Templeton launches tokenized ETF; Morgan Stanley to issue and sponsor Bitcoin ETF
Overview of Important Market Events on March 25
Kalshi early employees: Whoever controls the traffic controls the market
Robinhood can decide where tens of millions of contracts go with the flip of a switch, while the exchanges do all the hard work but cannot control their own fate.
Tether signs contracts with four major audits, Circle's compliance moat collapses, stock price plummets by 20%
USDT, with a market value of 184 billion dollars, is undergoing its first comprehensive inspection in history.
Proudly Introducing Aethir Claw: Your AI Agent, Our Infrastructure
Explore Aethir Claw, an easy-to-deploy AI agent solution that offers fully isolated VPS, encrypted payments, and highly competitive pricing.
Why Buying Gold Can Lead to Bankruptcy
"There is no issue with 'buying gold,' the issue is 'buying whose gold.'"
If the US Treasury yield rises above 5%, will Bitcoin drop below $50,000?
During the US-Iran war, as the bond market exhibited a **"meltdown"** scenario, Bitcoin's upward momentum is showing signs of exhaustion.
