COLDRIVER is a Russia-linked threat actor associated with phishing and credential-harvesting operations. The actor has been tracked under multiple names, including TAG-53, Callisto Group, and SEABORGIUM. Activity attributed to this cluster includes impersonation of organizations in defense, aerospace, logistics, satellite communications, nonprofit, and government-related contexts, with lures aligned to subjects of likely intelligence interest to Russian state-linked collection priorities, including matters connected to the war in Ukraine. Observed tradecraft includes phishing infrastructure designed to spoof legitimate sign-in experiences, including Microsoft-themed login pages, in order to steal victim credentials. Infrastructure clustering has been linked through recurring registrar choices, autonomous system usage, domain naming conventions, and TLS certificate patterns. Available reporting supports assessment of a Russia-linked espionage-oriented actor focused on credential theft and related initial access operations rather than ransomware or disruptive activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting phishing and credential-harvesting campaigns using spoofed domains and fake Microsoft login pages while impersonating defense, aerospace, logistics, nonprofit, satellite communications, and government-related entities.
Referenced as a newly added threat actor in MISP Galaxy; no operational details are provided in the content.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.