In partnership with Access Now and various civil society groups, Citizen Lab has uncovered a sophisticated cyber attack known as “Rivers of Phishing,” targeting adversaries of Russia worldwide.
This investigation revealed that the campaign employed a coordinated spear-phishing strategy aimed at select individuals across diverse countries and sectors within civil society. The attackers utilized advanced digital techniques to breach the security of activists, journalists, and human rights advocates.
Technical Overview
The group behind these attacks, identified as COLDRIVER (also referred to as Star Blizzard or TA446), is supported by Russia’s FSB. This group orchestrates a carefully crafted phishing initiative dubbed “River of Phish,” focusing on opposition figures, journalists, NGOs, academics, and policymakers concerned with Russia, Ukraine, and Belarus.
The attackers deploy highly personalized emails masquerading as trusted contacts. Often, these emails carry malware embedded in encrypted PDF files. These PDFs link to phishing sites designed to capture login credentials and evade two-factor authentication systems. Additionally, the PDFs typically share similar metadata structures and common English author names.
The campaign’s infrastructure relies on domains registered through Hostinger, which utilize JavaScript for initial target fingerprinting.
“If a target clicks on the link, their browser loads JavaScript from the attacker’s server, creating a fingerprint of the system and transmitting it back to the server.”
Notable victims include Polina Machold from Proekt Media and former US Ambassador Steven Pifer.
This campaign reflects evolving tactics aimed at evading detection, such as shifting domain registration from Namecheap to Hostinger.
Another related campaign, known as COLDWASTREL, employs different PDF characteristics and features a more intricate infrastructure, aligning with Russian cyber espionage activities. This behavior is consistent with broader Russian state objectives and poses a significant threat to victims, particularly those in Russian territories.
Despite their advanced capabilities, state-sponsored actors like Russia’s FSB rely on personalized phishing due to its cost-effectiveness and high success rate. These campaigns involve extensive intelligence gathering to craft convincing lures, with each successful attack providing data for future operations.
This persistence underscores the risky nature of COLDRIVER’s activities, potentially fueled by state backing.
These phishing campaigns frequently target civil society, as well as government and industry sectors often overlooked by cybersecurity reports. Russian cyber espionage encompasses a range of tactics, including censorship, stalking, account hijacking, and sophisticated social engineering methods.
Such multi-faceted strategies are particularly hazardous for activists, journalists, and NGOs focused on Russian-related issues, highlighting the critical need for robust security measures.
Recommendations
To mitigate risks, we recommend the following:
- Implement two-factor authentication.
- Participate in high-risk user programs.
- Avoid clicking on suspicious links from unknown sources.
- Be cautious of encrypted or protected PDFs.
- Utilize strong security solutions.
- Use complex passwords and update them regularly.
Indicators of Compromise
Here are some hashes of PDFs associated with COLDRIVER:
- b07d54a178726ffb9f2d5a38e64116cbdc361a1a0248fb89300275986dc5b69d
- 0ded441749c5391234a59d712c9d8375955ebd3d4d5848837b8211c6b27a4e88
- efa2fd8f8808164d6986aedd6c8b45bb83edd70ca4e80d7ff563a3fbc05eab89
- c1fa7cd73a14946fc760a54ebd0c853fab24a080cbf6b8460a949f28801e16fc
- 603221a64f2843674ad968970365f182c228b7219b32ab3777c265804ef67b0a
- df9d77f3e608c92ef899e5acd1d65d87ce2fdb9aab63bbf58e63e6fd6c768ac3
- 384d3027d92c13da55ceef9a375e8887d908fd54013f49167946e1791730ba22
- 79f93e57ad6be28aae62d14135140289f09f86d3a093551bd234adc0021bb827
- 00664f72386b256d74176aacbe6d1d6f6dd515dd4b2fcb955f5e0f6f92fa078e



