By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Pratzo - Daily NewsPratzo - Daily NewsPratzo - Daily News
Notification Show More
Font ResizerAa
  • Technology
    • AI & Machine Learning
    • Software & Apps
    • Hardware & Gadgets
    Technology
    Show More
    Top News
    Dubai's MBS Global Investments to Build $9 Billion Financial Hub in the Maldives: Report
    May 5, 2025
    WhatsApp Reportedly Testing Events Scheduling Feature in Individual Chats for iOS and Android Users
    February 1, 2025
    Kenya Orders Sam Altman's World to Delete Citizens' Biometric Data Within 7 Days
    May 6, 2025
    Latest News
    Alienware Area-51, Alienware Aurora Desktops With Latest Intel Core Ultra CPUs Launched in India
    July 2, 2025
    Grammarly Announces Plans to Acquire Email App Superhuman to Create Agentic Productivity Platform
    July 2, 2025
    Amazon Prime Day 2025 Sale: Discounts on Electronics and Bank Offers Revealed
    July 2, 2025
    WWE 2K25 Launches on Nintendo Switch 2 This Month, Pre-Orders Now Live
    July 2, 2025
  • Digital Marketing
    • Social Media Updates
    • PPC & Ads Insights
    • SEO Trends
    • Content Marketing Strategies
    Digital MarketingShow More
    70% of Senior Marketers Support Google’s Decision to Retain Third-Party Cookies on Chrome
    December 6, 2024
  • Lifestyle & Productivity
    • Personal Productivity Tools
    • Smart Home Tech
    • Wearables
    • Wellness Gadgets
    Lifestyle & ProductivityShow More
    Allu Arjun’s Bail Hearing Postponed to January 3
    December 31, 2024
    Pushpa 2 Full Movie Leaked Online
    Pushpa 2 Full Movie Leaked Online: A Major Setback Despite Record Pre-Sales
    December 5, 2024
    Pushpa 2: The Rule Movie Review – A Gripping Mass Entertainer
    December 5, 2024
  • Automobile
    AutomobileShow More
    New Petrol Price in India: Crude Oil Prices Fall – Check Today’s Rates
    January 25, 2025
    All-New Honda Amaze 2025 Launched in India – Prices Start at ₹7.99 Lakh
    December 5, 2024
    Mahindra XEV 9e Launched In India Priced At ₹ 21.90 Lakh: Check Range, Features, and More
    November 27, 2024
Reading: Google Identifies Lostkeys, a Russian Malware That Can Steal Specific Files and Directories
Share
Font ResizerAa
Pratzo - Daily NewsPratzo - Daily News
Search
Follow US
Pratzo - Daily News > Technology > Google Identifies Lostkeys, a Russian Malware That Can Steal Specific Files and Directories
Technology

Google Identifies Lostkeys, a Russian Malware That Can Steal Specific Files and Directories

admin
Last updated: May 13, 2025 3:29 am
admin Published May 13, 2025
Share
SHARE

Google Threat Intelligence Group (GTIG) shared a report about a new piece of malware last week. The new malware, dubbed Lostkeys, is described as a data theft malware and is said to be linked with the Russian threat group Coldriver. Lostkeys is considered dangerous because it is being spread at the end of a multi-step chain that starts with a lure website. The malware can steal specific files from a hard-coded list of extensions and directories. Additionally, it can also send system information and running processes to the attacker.

New Malware Linked to Russian Threat Group Coldriver Identified

In a blog post, the Mountain View-based tech giant highlighted that the newly discovered malware was first observed in January, followed by multiple observations in March and April. It appears to be the new tool in the arsenal of the threat group Coldriver (also known as UNC4057, Star Blizzard, and Callisto).

Notably, Google highlights that Coldriver is known for running credential phishing against targets such as NATO governments, non-governmental organisations (NGOs), as well as militaries, journalists, and diplomatic officers. The group was associated with the Spica malware in 2024.

The modus operandi (MO) of the group is trickier than typical phishing attacks. First, fake emails impersonating legitimate institutions are shared with victims. These emails contain website links. These are lure websites that feature fake CAPTCHA to convince the victim of their legitimacy. When the user confirms the CAPTCHA, PowerShell is copied to the user’s clipboard.

Notably, PowerShell is a command-line shell and scripting language primarily used for system administration, automation, and configuration management in Windows environments. Because PowerShell is built into Windows and has deep system access, it’s often abused by attackers to download and execute malware in memory.

Once the PowerShell has been copied, the page prompts the user to execute it via the “run” prompt. Once the user has done that, it triggers the second stage, which is focused on calculating the MD5 hash of the display resolution of the device. It is typically followed by a third stage to evade execution in virtual machines (in case it did not detect MD5 in the second step).

After this, another code execution retrieves and decodes the final payload, which is a visual basic script (VBS) file, otherwise known as Lostkeys. GTIG highlights that it is capable of “stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.”

Google states that Coldriver typically uses malware to steal emails and contacts from targets; however, at times, it is also known to deploy malware such as Spica to access documents on the target system. Lostkeys also enables a similar goal.

Notably, the tech giant has added all the identified malicious websites, domains, and files to Safe Browsing in Google Chrome to protect users from exploitation. Additionally, it is also sending government-backed attacker alerts to targeted Gmail and Workspace users. These alerts notify users about the threat and encourage them to enable Enhanced Safe Browsing.

source

You Might Also Like

Alienware Area-51, Alienware Aurora Desktops With Latest Intel Core Ultra CPUs Launched in India

Grammarly Announces Plans to Acquire Email App Superhuman to Create Agentic Productivity Platform

Amazon Prime Day 2025 Sale: Discounts on Electronics and Bank Offers Revealed

WWE 2K25 Launches on Nintendo Switch 2 This Month, Pre-Orders Now Live

Ferrari Amalfi Unveiled With Twin-Turbo V8 Engine, 320 KMPH Claimed Top Speed

TAGGED:Satellite TechnologySpace TechnologyTechnology
Share This Article
Facebook Twitter Email Print
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Current Gold Rate: 3681.90 INR per gram

Follow US

Find US on Social Medias
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

    Popular News
    Technology

    Google Photos for Android Gets New Grid Customisations to Reduce Clutter

    admin admin February 6, 2025
    Google Accidentally Leaks Material 3 ‘Expressive’ Design for Android Ahead of I/O 2025
    Gemini for iOS Updated With Six New Lockscreen Widgets, Control Centre Access
    Vivo V50 Leaked Live Images Suggest SoC, RAM Details Ahead of Imminent India Launch
    Samsung Galaxy F16 5G Price in India Revealed: Offers, Availability Details
    - Advertisement -
    Ad imageAd image

    Always Stay Up to Date

    Subscribe to our newsletter to get our newest articles instantly!

      About US

      At News.Pratzo.com, we are shaping the conversation in business and technology with reliable insights and updates. As part of the Pratzo.com brand, we aim to be your trusted source for impactful stories and trends, empowering professionals and enthusiasts alike. Stay informed, inspired, and ahead with us!
      Quick Link
      • Automobile
      • News
      • Cricket
      • Lifestyle & Productivity
      • Entertainment
      • Reviews & Comparisons
      • Digital Marketing
      • SEO Trends
      • Technology
      • AI & Machine Learning

      © Flair Hair & Beauty Salon London 2025

      © Pratzo News Network. Assets of Pratzo.com . All Rights Reserved.
      Go to mobile version