Citizen Lab and Access Now documented a sophisticated spear-phishing campaign targeting Russian opposition figures, Belarusian and Russian civil society groups, independent media, international NGOs active in Eastern Europe, policy experts, funders, journalists, and at least one former U.S. ambassador. Researchers attributed one cluster to COLDRIVER—also tracked as Star Blizzard, Callisto, TA446, Blue Charlie, and UNC4057—a Russia-linked threat actor that multiple governments have associated with the FSB’s Centre 18, while identifying a separate but related phishing cluster as COLDWASTREL.
The operations used highly personalized impersonation emails sent from compromised or lookalike accounts, along with fake encrypted or protected PDF lures that redirected victims through fingerprinting infrastructure to credential-harvesting pages spoofing services such as Gmail and ProtonMail. Investigators found overlaps with known COLDRIVER tradecraft, including Hostinger-registered domains, Let’s Encrypt or ZeroSSL certificates, LibreOffice 7.0 PDF metadata, randomized author names, and occasional HubSpot links, while COLDWASTREL showed distinct metadata, infrastructure, and domain patterns. The groups sought passwords, two-factor authentication codes, and session cookies, raising the risk of exposing sensitive identities, communications, relationships, and locations of organizations already facing Russian government repression.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Citizen Lab published a detailed report on the 'River of Phish' spear-phishing campaign targeting Russian opposition figures, journalists, NGOs, funders, media, and policy experts across multiple countries. The report attributed the activity to COLDRIVER and documented overlaps with prior infrastructure and lures, while also distinguishing a separate cluster named COLDWASTREL.
Access Now’s Digital Security Helpline and the Citizen Lab, with partner organizations, disclosed at least two spear-phishing campaigns targeting Russian and Belarusian civil society, independent media, international NGOs in Eastern Europe, and at least one former U.S. ambassador. They attributed one campaign to COLDRIVER and identified a second distinct actor they named COLDWASTREL.
Investigators began tracking activity later attributed to the newly named COLDWASTREL phishing cluster after receiving reports of attacks targeting civil society communities. The campaign used social engineering and infrastructure impersonating prominent Eastern European civil society organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 113 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
7 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourceaccessnow.org
Open sourcecitizenlab.ca
Open sourceblog.google
Open sourceblog.sekoia.io
Open sourcecepa.org
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.