PULSE NAME
Rivers of Phish: Sophisticated Phishing Targets Russia's Perceived Enemies Around the Globe
WHITE COLDWASTREL AlienVault 2024-08-14 Modified: 2024-08-14
28
IOCs
MEDIUM VOLUME
An extensive investigation uncovered an elaborate phishing campaign conducted by a Russia-based threat actor known as COLDRIVER, attributed to Russia's Federal Security Service. The campaign employed personalized social engineering tactics to target civil society groups, NGOs, journalists, and government entities perceived as adversaries. A separate threat actor called COLDWASTREL, potentially aligned with Russian interests, was also identified employing similar techniques. The report details the intricate methods used, including impersonating known individuals, crafting credible lures, and harvesting credentials for account takeovers, underscoring the persistent threats facing civil society from state-backed cyber operations.
Indicators of Compromise (28)
All FileHash-SHA256 domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 00664f72386b256d74176aacbe6d1d6f6dd515dd4b2fcb955f5e0f6f92fa078e 2024-08-14
FileHash-SHA256 0ded441749c5391234a59d712c9d8375955ebd3d4d5848837b8211c6b27a4e88 2024-08-14
FileHash-SHA256 384d3027d92c13da55ceef9a375e8887d908fd54013f49167946e1791730ba22 2024-08-14
FileHash-SHA256 4a9a2c2926b7b8e388984d38cb9e259fb4060cccc2d291c7910be030ae5301a3 2024-08-14
FileHash-SHA256 603221a64f2843674ad968970365f182c228b7219b32ab3777c265804ef67b0a 2024-08-14
FileHash-SHA256 79f93e57ad6be28aae62d14135140289f09f86d3a093551bd234adc0021bb827 2024-08-14
FileHash-SHA256 b07d54a178726ffb9f2d5a38e64116cbdc361a1a0248fb89300275986dc5b69d 2024-08-14
FileHash-SHA256 c1fa7cd73a14946fc760a54ebd0c853fab24a080cbf6b8460a949f28801e16fc 2024-08-14
FileHash-SHA256 df9d77f3e608c92ef899e5acd1d65d87ce2fdb9aab63bbf58e63e6fd6c768ac3 2024-08-14
FileHash-SHA256 efa2fd8f8808164d6986aedd6c8b45bb83edd70ca4e80d7ff563a3fbc05eab89 2024-08-14
domain egenre.net 2024-08-14
domain eilatocare.com 2024-08-14
domain esestacey.net 2024-08-14
domain ideaspire.net 2024-08-14
domain ithostprotocol.com 2024-08-14
domain matalangit.org 2024-08-14
domain proton-docs.com 2024-08-14
domain proton-reader.com 2024-08-14
domain proton-viewer.com 2024-08-14
domain protondrive.me 2024-08-14
domain protondrive.online 2024-08-14
domain protondrive.services 2024-08-14
domain resident.ngo 2024-08-14
domain service-proton.me 2024-08-14
domain togochecklist.com 2024-08-14
domain vocabpaper.com 2024-08-14
domain xsltweemat.org 2024-08-14
hostname dj-kqf04.eu1.hubspotlinksfree.com 2024-08-14