Citizen Lab and Access Now documented a sophisticated spear-phishing campaign targeting Russian opposition figures, Belarusian and Russian civil society groups, independent media, international NGOs active in Eastern Europe, policy experts, funders, journalists, and at least one former U.S. ambassador. Researchers attributed one cluster to COLDRIVER—also tracked as Star Blizzard, Callisto, TA446, Blue Charlie, and UNC4057—a Russia-linked threat actor that multiple governments have associated with the FSB’s Centre 18, while identifying a separate but related phishing cluster as COLDWASTREL.
The operations used highly personalized impersonation emails sent from compromised or lookalike accounts, along with fake encrypted or protected PDF lures that redirected victims through fingerprinting infrastructure to credential-harvesting pages spoofing services such as Gmail and ProtonMail. Investigators found overlaps with known COLDRIVER tradecraft, including Hostinger-registered domains, Let’s Encrypt or ZeroSSL certificates, LibreOffice 7.0 PDF metadata, randomized author names, and occasional HubSpot links, while COLDWASTREL showed distinct metadata, infrastructure, and domain patterns. The groups sought passwords, two-factor authentication codes, and session cookies, raising the risk of exposing sensitive identities, communications, relationships, and locations of organizations already facing Russian government repression.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Citizen Lab published a detailed report on the 'River of Phish' spear-phishing campaign targeting Russian opposition figures, journalists, NGOs, funders, media, and policy experts across multiple countries. The report attributed the activity to COLDRIVER and documented overlaps with prior infrastructure and lures, while also distinguishing a separate cluster named COLDWASTREL.
Access Now’s Digital Security Helpline and the Citizen Lab, with partner organizations, disclosed at least two spear-phishing campaigns targeting Russian and Belarusian civil society, independent media, international NGOs in Eastern Europe, and at least one former U.S. ambassador. They attributed one campaign to COLDRIVER and identified a second distinct actor they named COLDWASTREL.
Investigators began tracking activity later attributed to the newly named COLDWASTREL phishing cluster after receiving reports of attacks targeting civil society communities. The campaign used social engineering and infrastructure impersonating prominent Eastern European civil society organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourceaccessnow.org
Open sourcecitizenlab.ca
Open sourceblog.google
Open sourceblog.sekoia.io
Open sourcecepa.org
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.