Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

New LOSTKEYS Malware Tied to Russian State-Sponsored Hacker Group COLDRIVER

The Russian state-sponsored threat actor known as COLDRIVER has been linked to a rapidly evolving malware campaign following the public disclosure of its LOSTKEYS malware in May 2025. Previously known for targeting high-profile NGOs, policy advisors, and…

The Russian state-sponsored threat actor known as COLDRIVER has been linked to a rapidly evolving malware campaign following the public disclosure of its LOSTKEYS malware in May 2025. Previously known for targeting high-profile NGOs, policy advisors, and dissidents, the group has demonstrated agility by shifting its tactics and tools in response to this exposure.

After the disclosure of LOSTKEYS, COLDRIVER, also tracked as UNC4057, Star Blizzard, and Callisto, ceased the use of this compromised malware. Within five days, the group operationalized new malware families. This shift involved deploying a diverse toolset featuring interconnected malware families that have undergone several development iterations. This rapid adaptation illustrates the group's dedication to maintaining access to targeted environments and evading defensive measures.

A central component of this new toolset is a malicious DLL named NOROBOT. Delivered via an updated "ClickFix" lure, which poses as a CAPTCHA challenge, NOROBOT is designed to retrieve additional malicious stages from hardcoded command-and-control (C2) servers. This represents a departure from COLDRIVER's previous reliance on complex PowerShell chains, opting instead to trick users into executing a DLL with rundll32, thereby evading some traditional security controls.

The new attack chain commences when targets interact with a fake CAPTCHA page, prompting them to execute a DLL disguised as “iamnotarobot.dll.” NOROBOT, also referred to as BAITSWITCH by Zscaler, is in constant development. Samples observed from May through September 2025 reveal a balance between simplified deployment to increase infection rates and added complexity, such as splitting cryptographic keys across multiple components to hinder analysis.

After the disclosure of LOSTKEYS, COLDRIVER, also tracked as UNC4057, Star Blizzard, and Callisto, ceased the use of this compromised malware.
Madison Drake · Thehackingpost

Initial versions of NOROBOT led to the deployment of a Python backdoor named YESROBOT, which required a full Python installation, increasing the risk of detection. However, GTIG observed its brief use before COLDRIVER replaced it with a PowerShell-based backdoor named MAYBEROBOT (or SIMPLEFIX). This new backdoor eliminated the need for Python and offered a more versatile command protocol.

Each variant of NOROBOT incorporates subtle changes, such as rotating infrastructure and altering file names and export functions, to evade detection and complicate incident response. The final backdoor, MAYBEROBOT, remains stable, suggesting a focus on fortifying the infection chain itself to increase resilience against takedowns and analyses.

Phishing vs. Malware—and Community Defense

Although COLDRIVER historically favored phishing attacks, the intensified use of malware might be reserved for high-value targets requiring device-level intelligence after initial account compromises. In response, Google has added malicious infrastructure and samples to Safe Browsing and sent threat notifications to at-risk Gmail and Workspace users.

Advertisement

Security professionals are encouraged to review shared indicators of compromise (IOCs) and YARA rules and to stay updated on emerging COLDRIVER campaigns via threat intelligence feeds. As COLDRIVER's tactics continue to evolve, defenders must adapt, remaining vigilant against both traditional lures and sophisticated malware chains used in Russian state espionage operations.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories