Description

Access Now and Citizen Lab have found two Russia-connected threat groups carrying out complex spear-phishing attacks on organizations seen as Russian opponents. One group Coldwastrel, is quite new but works in line with Russian government goals. These attackers send custom phishing emails often pretending to be coworkers or government officials, with tricky PDF attachments that take victims to fake sites made to steal login info, including passwords and two-step verification details. The phishing web addresses set up with Hostinger, change often to avoid being caught and stay active for short times. While these specific attacks didn't have malware, the threat groups' ongoing efforts and advanced methods pose a big risk to high-profile targets like NGOs, news outlets, and Russian opposition members. Citizen Lab cautions that if these attacks succeed, they could lead to serious outcomes such as jail time or physical danger. These attacks, which have gone on into August 2024, show the ongoing threat to those working on sensitive issues related to Russia, Ukraine, or Belarus. These campaigns might also target US government groups highlighting the need for better security measures.