Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

Filtered by source: google-threat-intel Clear filter
To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog

3w ago · google-threat-intel

Russian state-sponsored threat group COLDRIVER rapidly deployed new malware families following the public disclosure of its LOSTKEYS malware in May 2025. The group introduced a new infection chain centered around the NOROBOT DLL, delivered via a 'ClickFix' CAPTCHA-themed lure, leading to deployment of the YESROBOT and later MAYBEROBOT backdoors. COLDRIVER has shown aggressive development tempo, frequently evolving delivery mechanisms and evasion techniques to maintain access to high-value targets such as NGOs, policy advisors, and dissidents.

22 IoCs 1 Actors 4 Malware