Free, Unbiased, and Open threat intelligence

To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER

threat Profile

Description

Russian state-sponsored threat group COLDRIVER (also known as UNC4057, Star Blizzard, and Callisto) swiftly shifted operations after the May 2025 public disclosure of its LOSTKEYS malware, operationalizing new malware families within five days. The threat actor has deployed a collection of related malware families connected via a delivery chain, including NOROBOT (also known as BAITSWITCH), YESROBOT, and MAYBEROBOT (also known as SIMPLEFIX). The infection chain begins with an updated COLDCOPY 'ClickFix' lure disguised as a CAPTCHA that tricks users into executing a malicious DLL via rundll32. NOROBOT serves as a downloader that retrieves subsequent stages from hardcoded C2 servers. Initially, COLDRIVER deployed YESROBOT, a cumbersome Python backdoor requiring a full Python 3.8 installation, but quickly replaced it with MAYBEROBOT, a more flexible PowerShell backdoor. The malware has undergone multiple iterations with constant evolution in the infection chain, including simplification for deployment success and later re-introduction of complexity through split cryptography keys to evade detection. COLDRIVER targets high-profile individuals in NGOs, policy advisors, and dissidents for intelligence collection. The group demonstrates increased development tempo and aggressive deployment against high-value targets.

MITRE ATT&CK Techniques

T1566.002 T1204.002 T1218.011 T1027 T1105 T1547.001 T1053.005 T1059.001 T1071.001 T1140 T1082 T1033 T1041

Related Entities

Indicators of Compromise (5)

2e74f6bd9bf73131d3213399ed2f669ec5f75392de69edf8ce8196cd70eb6aee
Earliest version of NOROBOT DLL
3b49904b68aedb6031318438ad2ff7be4bf9fd865339330495b177d5c4be69d1
Simplified variant of NOROBOT from June 2025
inspectguarantee.org
C2 domain used to retrieve libsystemhealthcheck.py and libcryptopydatasize.py
b60100729de2f468caf686638ad513fe28ce61590d2b0d8db85af9edc5da98f9
MAYBEROBOT heavily obfuscated PowerShell script
c4d0fba5aaafa40aef6836ed1414ae3eadc390e1969fdcb3b73c60fe7fb37897
COLDCOPY ClickFix lure variant

Metadata

Published

7 months ago

Views

0