Spica
SPICA is a custom malware backdoor and data-theft tool associated with the Russian state-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, SEABORGIUM, UNC4057, and IRON FRONTIER. Google Threat Analysis Group reported in January 2024 that SPICA was the first known case of COLDRIVER developing and deploying custom malware. The malware has been used selectively against specific individuals as part of COLDRIVER espionage operations to access documents stored on compromised Windows systems.
Observed capabilities include persistence via a scheduled task, including creation of a task named "CalendarChecker," and use of obfuscated PowerShell to establish that persistence. SPICA can steal browser cookies from Chrome, Firefox, Opera, and Microsoft Edge. It can archive collected documents for exfiltration and uses JSON over WebSockets for command-and-control communications.
The supporting content links SPICA to COLDRIVER’s broader targeting of high-value individuals and civil society-related victims connected to Russian intelligence requirements, including NGOs, human rights defenders, think tanks, journalists, and other persons of interest. SPICA is also referenced alongside later COLDRIVER malware such as LOSTKEYS, with reporting describing LOSTKEYS as reminiscent of SPICA but more advanced in architecture and delivery.
Hunt this family in your stack
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
Groups observed using it
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Lostkeys is reminiscent of Spica, a previous malware strain used by Coldriver in 2024. While Spica was also designed for data theft, Lostkeys shows a refined architecture and more advanced delivery mechanisms.
Techniques & procedures
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Initial Access
1 techniqueIRON FRONTIER is a Russian threat group that conducts targeted spearphishing against military and government organizations, journalists, and think tanks in Europe, the United States, and Russia's near abroad.
Execution
3 techniques“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
"During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines" and "Spica can use an obfuscated PowerShell command to create a scheduled task for persistence."
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
Persistence
2 techniques“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Privilege Escalation
2 techniques“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Stealth
4 techniquesExamples include "APT29 has used encoded PowerShell scripts...", "Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell", "During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file", and "Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender."
APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
Credential Access
1 technique"...used custom malware to steal login and cookie data from common browsers..."; "...extracts the web session cookie and sends it to the C2 server..."; "...stole Chrome browser cookies by copying the Chrome profile directories..."
Discovery
1 techniqueCollection
1 techniqueMultiple malware and groups are described as zipping/archiving/packing collected data prior to exfiltration (e.g., "used ZIP to compress data gathered on a compromised host", "packs collected data into a password protected archive", "archived victim's data prior to exfiltration").
Command and Control
3 techniques"Mythic supports WebSocket and TCP-based C2 profiles." / "Spica can use JSON over WebSockets for C2 communications."
Recent activity
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware family publicly reported/attributed to COLDRIVER by Google TAG in 2024 (per the content). No additional technical characteristics are included here.
Previously used Coldriver malware used to target specific individuals and access documents on compromised systems.
...custom tools like SPICA and LOSTKEYS...
SPICA is a malware previously used by the COLDRIVER group for credential phishing and targeted espionage operations.
The version that knows your environment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.