To Be (A Robot) or Not to Be: New Malware Attributed to Russia State-Sponsored COLDRIVER | Google Cloud Blog
3w ago · google-threat-intel
Russian state-sponsored threat group COLDRIVER rapidly deployed new malware families following the public disclosure of its LOSTKEYS malware in May 2025. The group introduced a new infection chain centered around the NOROBOT DLL, delivered via a 'ClickFix' CAPTCHA-themed lure, leading to deployment of the YESROBOT and later MAYBEROBOT backdoors. COLDRIVER has shown aggressive development tempo, frequently evolving delivery mechanisms and evasion techniques to maintain access to high-value targets such as NGOs, policy advisors, and dissidents.
22 IoCs 1 Actors 4 Malware