Threat intelligence
- Suspected origin
- Russia
- First seen
- 2019-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Defense, NGOs, Think Tanks
- TLP
- WHITE
(Lastline) While reviewing some network anomalies, we recently uncovered Cold River, a sophisticated threat actor making malicious use of DNS tunneling for command and control activities. We have been able to decode the raw traffic in command and control, find sophisticated lure documents used in the campaign, connect other previously unknown samples, and associate a number of legitimate organizations whose infrastructure is referenced and used in the campaign.
The campaign targets Middle Eastern organizations largely from the Lebanon and United Arab Emirates, though, Indian and Canadian companies with interests in those Middle Eastern countries are also targeted. There are new TTPs used in this attack – for example Agent_Drable is leveraging the Django python framework for command and control infrastructure, the technical details of which are outlined later in the blog.
Also known as
Blue CallistoBlueCharlieCalistoCallisto GroupCobalt EdgewaterCOLDRIVERGossamer BearGrey ProIRON FRONTIERMythic UrsaNahr el baredNahr ElbardSeaborgiumStar BlizzardTA446TAG-53UNC4057
MITRE ATT&CK techniques
T1539 Steal Web Session CookieT1589 Gather Victim Identity InformationT1593 Search Open Websites/DomainsT1583 Acquire InfrastructureT1078 Valid Accounts
Coverage 3
vulnerability
A new variant of the DarkSword iOS exploit kit, dubbed P7 DarkSword, has emerged, exhibiting enhanced stealth and data theft capabilities. The kit leverages multiple vulnerabilities, including CVE-2025-24201 and CVE-2025…

vulnerability
This week’s cybersecurity news highlights a mix of active exploits and emerging threats. Simultaneously, law enforcement has arrested two ShinyHunters members, and a 16-year-old ransomware leader has been apprehended. Ad…

malware
Russian state-sponsored hackers, known as Star Blizzard, are using fake event invitations to deliver a backdoor onto Windows computers. They use various techniques, including phishing emails, exploit kits (like DarkSword…
