COLDWASTREL is a distinct spear-phishing threat actor targeting Russian and Belarusian civil society, Russian independent media, international NGOs active in Eastern Europe, and at least one former U.S. ambassador. The actor’s targeting aligns with Russian government interests, but attribution to a specific organization or state entity remains unconfirmed. COLDWASTREL has been assessed as separate from COLDRIVER despite overlap in victim communities and broad operational objectives. The actor specializes in highly tailored social-engineering operations. Observed lures include emails sent from compromised or lookalike accounts that impersonate trusted contacts and reference plausible professional topics such as events, funding, or document review. A common technique uses fake protected or encrypted PDF documents that direct victims to credential-harvesting login pages. Reported tradecraft also includes browser fingerprinting prior to redirection and theft of passwords, two-factor authentication material, and session data to enable unauthorized access to email accounts. COLDWASTREL’s operations appear focused on account compromise rather than malware deployment. The likely objective is intelligence collection through access to victims’ communications, contacts, activities, and relationships. This creates elevated legal, operational, and physical risk for targeted Russian and Belarusian organizations and individuals, particularly those already exposed to state repression. Known reporting identifies COLDWASTREL as an actor serving Russian state interests, but currently stops short of confident attribution to a named Russian government service or subordinate unit.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A distinct phishing cluster targeting similar civil society communities with credential-harvesting lures themed around ProtonDrive, using malicious PDFs and directly hosted phishing kits rather than the multi-stage COLDRIVER flow.
Conducting spear-phishing campaigns against civil society targets, including international NGOs active in Eastern Europe, using impersonation, compromised or lookalike email accounts, and fake login pages embedded via seemingly locked PDF lures to harvest credentials.
COLDWASTREL is a distinct threat actor observed targeting Russian civil society and related communities with personalized phishing campaigns. The group uses malicious PDFs referencing ProtonMail/ProtonDrive to lure targets, but with different infrastructure and document characteristics from COLDRIVER. The targeting aligns with Russian government interests, but explicit attribution is not made.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.