SPICA is a custom malware backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, TA446, Blue Callisto, Blue Charlie, UNC4057, and IRON FRONTIER. Google Threat Analysis Group reported in January 2024 that SPICA was the first known case of COLDRIVER developing and deploying custom malware. The malware has been used selectively against specific high-value individuals as part of COLDRIVER espionage activity, including efforts to access documents stored on compromised systems. Reported capabilities include persistence via an obfuscated PowerShell command that creates a scheduled task named CalendarChecker, cookie theft from Chrome, Firefox, Opera, and Edge, command-and-control communications over JSON via WebSockets, and archiving collected documents for exfiltration. Supporting content characterizes SPICA as a data-theft-oriented backdoor and notes it as a predecessor to COLDRIVER’s later LOSTKEYS malware. The broader actor has historically targeted civil society, NGOs, journalists, think tanks, government-related individuals, and Russian opposition-linked communities, particularly those connected to Russia, Ukraine, and Belarus. No additional high-confidence indicators of compromise beyond the CalendarChecker scheduled task name are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In January of 2024, Google’s Threat Analysis Group (TAG) reported on a custom malware backdoor called SPICA, which they assessed was the first known case of COLDRIVER developing and deploying custom malware.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
"During the SolarWinds Compromise, APT29 used PowerShell to create new tasks on remote machines" and "Spica can use an obfuscated PowerShell command to create a scheduled task for persistence."
The content repeatedly describes threat actors and malware using PowerShell scripts/commands for execution, download, staging, reconnaissance, persistence, credential access, lateral movement, and defense evasion; e.g., "Sandworm Team used PowerShell scripts to run a credential harvesting tool in memory to evade defenses."
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
Examples include "APT29 has used encoded PowerShell scripts...", "Aquatic Panda has downloaded additional scripts and executed Base64 encoded commands in PowerShell", "During C0021, the threat actors used obfuscated PowerShell to extract an encoded payload from within an .LNK file", and "Play has used Base64-encoded PowerShell scripts to disable Microsoft Defender."
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Multiple malware and groups are described as zipping/archiving/packing collected data prior to exfiltration (e.g., "used ZIP to compress data gathered on a compromised host", "packs collected data into a password protected archive", "archived victim's data prior to exfiltration").
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom malware backdoor reportedly developed and deployed by COLDRIVER; described as the first known custom malware used by that threat actor.
A malware family publicly reported/attributed to COLDRIVER by Google TAG in 2024 (per the content). No additional technical characteristics are included here.
Previously used Coldriver malware used to target specific individuals and access documents on compromised systems.
...custom tools like SPICA and LOSTKEYS...
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.