The Russia-backed advanced persistent threat group ColdRiver, also known as UNC4057, Star Blizzard, and Callisto, has launched a new cyber espionage campaign targeting NATO governments, former diplomats, policy advisors, and high-profile NGO figures. Following the public disclosure of their LOSTKEYS credential-stealing malware by Google’s Threat Intelligence Group (GTIG) in May 2025, ColdRiver rapidly abandoned LOSTKEYS and pivoted to deploying a new suite of malware tools. Within five days of the LOSTKEYS exposure, the group had ceased all observed use of the platform and began leveraging new backdoors, including YESROBOT and MAYBEROBOT, distributed via a loader called NOROBOT. The initial infection vector in these campaigns involves a ClickFix CAPTCHA-style lure, which tricks users into executing a malicious file, thereby initiating the malware deployment process. The YESROBOT backdoor, written in Python, was first observed in late May 2025 and required a full Python 3.8 installation, with its decryption key split across multiple components as an anti-analysis measure. However, YESROBOT was considered cumbersome due to its operational requirements and limited extensibility. By early June 2025, ColdRiver had shifted to using MAYBEROBOT, a more streamlined PowerShell-based backdoor capable of downloading and executing content from a hardcoded command-and-control server, running commands via cmd.exe, and executing PowerShell blocks. The group continued to iterate on both NOROBOT and MAYBEROBOT throughout the summer, regularly rotating command-and-control infrastructure to evade detection. This rapid development and operational tempo highlight ColdRiver’s ability to adapt quickly when their tools are exposed. The campaigns demonstrate a shift from credential phishing without malware to the deployment of lightweight, modular backdoors, increasing the sophistication and persistence of their operations. Despite their technical agility, ColdRiver has experienced repeated operational security failures, which have allowed researchers to track their activities closely. The use of fake CAPTCHA lures and DLL execution via rundll32 marks a tactical evolution from previous PowerShell-based delivery methods. The group’s targets remain consistent, focusing on entities of strategic interest to Russian intelligence. GTIG’s ongoing monitoring has not observed any further use of LOSTKEYS since its exposure, confirming the group’s complete transition to the new malware suite. The campaigns underscore the importance of rapid threat intelligence sharing and the need for organizations to remain vigilant against evolving social engineering and malware delivery techniques. ColdRiver’s activities exemplify the persistent threat posed by state-sponsored actors capable of quickly retooling their operations in response to public disclosures. Organizations in the crosshairs of such groups should prioritize detection of novel malware loaders, backdoors, and social engineering lures, as well as maintain robust incident response capabilities.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
On October 21, 2025, Google Threat Intelligence Group disclosed three new COLDRIVER malware families—NOROBOT, YESROBOT, and MAYBEROBOT—and said the actor had increased its operational tempo since May 2025. Google also released indicators of compromise and YARA rules to help defenders detect the activity.
The Netherlands' Public Prosecution Service announced that three 17-year-old suspects were accused of providing services to a foreign government, including mapping Wi‑Fi networks in The Hague for possible espionage use. This development was reported alongside Google's findings on COLDRIVER but described as a separate case.
Later in the campaign, COLDRIVER swapped the short-lived YESROBOT implant for MAYBEROBOT, a more advanced PowerShell-based backdoor. Google assessed this reflected rapid malware iteration and a move toward a more capable follow-on implant.
In the earlier phase of the new toolchain, NOROBOT staged a Python 3.8 environment and delivered the YESROBOT backdoor. Google assessed YESROBOT was a short-lived interim implant used soon after the shift away from LOSTKEYS.
From June through September 2025, COLDRIVER used fake 'I am not a robot' CAPTCHA lures to trick targets into executing malicious commands via the Windows Run dialog. The delivery chain used COLDCOPY HTML lures to launch NOROBOT through rundll32.exe and establish follow-on access.
Within five days of Google's LOSTKEYS disclosure, COLDRIVER started deploying a new malware toolchain consisting of NOROBOT, YESROBOT, and later MAYBEROBOT. Google said it observed no further LOSTKEYS deployments after this pivot.
Google Threat Intelligence Group publicly reported on COLDRIVER's LOSTKEYS infostealer in May 2025. The disclosure exposed malware previously used against high-value targets including Western governments, journalists, think tanks, and NGOs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecsoonline.com
Open sourcebleepingcomputer.com
Open sourcethehackernews.com
Open sourceaustinlarsen.me
Open sourcedarkreading.com
Open sourcescworld.com
Open sourceaustinlarsen.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.