Threat group COLDRIVER is using new malware to steal documents from Western targets, according to a May 7 report from Google Threat Intelligence. The malware, called LOSTKEYS, shows the evolution of the group from credential phishing to more sophisticated attacks. According to the Google report, the new malware is installed through four steps. The process involves a “lure website” with a fake CAPTCHA, a PowerShell script downloaded to the user’s clipboard, some device evasion, and retrieval of the final payload
source: https://cointelegraph.com/news/coldriver-new-malware-steal-western-targets-google?utm_source=rss_feed&utm_medium=rss&utm_campaign=rss_partner_inbound