google-threat-intel · Crawled Jul 25, 2026
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog
22 IoCs 1 Actors 4 Malware
Read original article ↗
AI Summary
Russian state-sponsored threat group COLDRIVER rapidly deployed new malware families following the public disclosure of its LOSTKEYS malware in May 2025. The group introduced a new infection chain centered around the NOROBOT DLL, delivered via a 'ClickFix' CAPTCHA-themed lure, leading to deployment of the YESROBOT and later MAYBEROBOT backdoors. COLDRIVER has shown aggressive development tempo, frequently evolving delivery mechanisms and evasion techniques to maintain access to high-value targets such as NGOs, policy advisors, and dissidents.
AI-extracted · verify before operational use
Extracted Entities 5 found
Indicators of Compromise 22 extracted
| Type | Value | Detail |
|---|---|---|
| Domain | viewerdoconline[.]com | Details → |
| Domain | documentsec[.]com | Details → |
| Domain | documentsec[.]online | Details → |
| Domain | onstorageline[.]com | Details → |
| Domain | applicationformsubmit[.]me | Details → |
| Domain | oxwoocat[.]org | Details → |
| Domain | ned-granting-opportunities[.]com | Details → |
| Domain | blintepeeste[.]org | Details → |
| Domain | preentootmist[.]org | Details → |
| SHA-256 | c4d0fba5aaafa40aef6836ed1414ae3eadc390e1969fdcb3b73c60fe7fb37897 | Details → |
| Domain | inspectguarantee[.]org | Details → |
| Domain | captchanom[.]top | Details → |
| SHA-256 | bce2a7165ceead4e3601e311c72743e0059ec2cd734ce7acf5cc9f7d8795ba0f | Details → |
| Domain | system-healthadv[.]com | Details → |
| IP | 85[.]239[.]52[.]32 | Details → |
| SHA-256 | 2e74f6bd9bf73131d3213399ed2f669ec5f75392de69edf8ce8196cd70eb6aee | Details → |
| SHA-256 | 3b49904b68aedb6031318438ad2ff7be4bf9fd865339330495b177d5c4be69d1 | Details → |
| SHA-256 | e9c8f6a7dba6e84a7226af89e988ae5e4364e2ff2973c72e14277c0f1462109b | Details → |
| SHA-256 | b60100729de2f468caf686638ad513fe28ce61590d2b0d8db85af9edc5da98f9 | Details → |
| Domain | southprovesolutions[.]com | Details → |
| SHA-256 | f2da013157c09aec9ceba1d4ac1472ed049833bc878a23bc82fe7eacbad399f4 | Details → |
| SHA-256 | 87138f63974a8ccbbf5840c31165f1a4bf92a954bacccfbf1e7e5525d750aa48 | Details → |
MITRE ATT&CK TTPs 12 techniques
T1012 Query Registry · Discovery T1027 Obfuscated Files or Information · Defense Evasion T1053.005 Scheduled Task · Execution T1055 Process Injection · Defense Evasion T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1082 System Information Discovery · Discovery T1087.002 Domain Account · Discovery T1105 Ingress Tool Transfer · Command And Control T1140 Deobfuscate/Decode Files or Information · Defense Evasion T1204.002 Malicious File · Execution