Russian COLDRIVER Hackers Deploy LOSTKEYS Malware to Steal Sensitive Information
Essential information
- Published
- 10/05/2025 07:04
- Modified
- 12/05/2025 08:16
- Tags
- 2025-05-10 captcha intelligence collection lostkeys multi-stage infection nato ngo powershell russian hackers ukraine western governments
- Related entities
- 1 intrusion sets (apt), 15 techniques (mitre), 1 malware, 5 others
Description
The Google Threat Intelligence Group has identified a sophisticated malware called LOSTKEYS, attributed to the Russian government-backed threat actor COLDRIVER. Active since December 2023, LOSTKEYS represents an evolution in COLDRIVER's toolkit, targeting high-value entities such as NATO governments, NGOs, and former intelligence officers. The malware exfiltrates specific files, harvests system information, and targets individuals linked to Ukraine or Western governments. COLDRIVER's primary goal appears to be intelligence collection aligned with Russia's interests. The infection chain involves a complex multi-stage process, beginning with a fake CAPTCHA and employing various evasion tactics. Google has implemented countermeasures and recommends enhanced security measures for users.