New LOSTKEYS Malware Tied to Russian State-Sponsored Hacker Group COLDRIVER
The Russian state-sponsored threat actor known as COLDRIVER has been linked to a rapidly evolving malware campaign following the public disclosure of its LOSTKEYS malware in May 2025. Previously known for targeting high-profile NGOs, policy advisors, and…
The Russian state-sponsored threat actor known as COLDRIVER has been linked to a rapidly evolving malware campaign following the public disclosure of its LOSTKEYS malware in May 2025. Previously known for targeting high-profile NGOs, policy advisors, and dissidents, the group has demonstrated agility by shifting its tactics and tools in response to this exposure.
After the disclosure of LOSTKEYS, COLDRIVER, also tracked as UNC4057, Star Blizzard, and Callisto, ceased the use of this compromised malware. Within five days, the group operationalized new malware families. This shift involved deploying a diverse toolset featuring interconnected malware families that have undergone several development iterations. This rapid adaptation illustrates the group's dedication to maintaining access to targeted environments and evading defensive measures.
A central component of this new toolset is a malicious DLL named NOROBOT. Delivered via an updated "ClickFix" lure, which poses as a CAPTCHA challenge, NOROBOT is designed to retrieve additional malicious stages from hardcoded command-and-control (C2) servers. This represents a departure from COLDRIVER's previous reliance on complex PowerShell chains, opting instead to trick users into executing a DLL with rundll32, thereby evading some traditional security controls.
The new attack chain commences when targets interact with a fake CAPTCHA page, prompting them to execute a DLL disguised as “iamnotarobot.dll.” NOROBOT, also referred to as BAITSWITCH by Zscaler, is in constant development. Samples observed from May through September 2025 reveal a balance between simplified deployment to increase infection rates and added complexity, such as splitting cryptographic keys across multiple components to hinder analysis.
After the disclosure of LOSTKEYS, COLDRIVER, also tracked as UNC4057, Star Blizzard, and Callisto, ceased the use of this compromised malware.
Initial versions of NOROBOT led to the deployment of a Python backdoor named YESROBOT, which required a full Python installation, increasing the risk of detection. However, GTIG observed its brief use before COLDRIVER replaced it with a PowerShell-based backdoor named MAYBEROBOT (or SIMPLEFIX). This new backdoor eliminated the need for Python and offered a more versatile command protocol.
Each variant of NOROBOT incorporates subtle changes, such as rotating infrastructure and altering file names and export functions, to evade detection and complicate incident response. The final backdoor, MAYBEROBOT, remains stable, suggesting a focus on fortifying the infection chain itself to increase resilience against takedowns and analyses.
Phishing vs. Malware—and Community Defense
Although COLDRIVER historically favored phishing attacks, the intensified use of malware might be reserved for high-value targets requiring device-level intelligence after initial account compromises. In response, Google has added malicious infrastructure and samples to Safe Browsing and sent threat notifications to at-risk Gmail and Workspace users.
Security professionals are encouraged to review shared indicators of compromise (IOCs) and YARA rules and to stay updated on emerging COLDRIVER campaigns via threat intelligence feeds. As COLDRIVER's tactics continue to evolve, defenders must adapt, remaining vigilant against both traditional lures and sophisticated malware chains used in Russian state espionage operations.
Based on reporting by GBHackers.
