Beyond the Breaking News

Russia-Linked Phishing Attacks Targeted NGOs And Ex-U.S. Ambassador

Access Now News

Russia-Linked Phishing Attacks Targeted NGOs And Ex-U.S. Ambassador
Citizen LabsColdriverColdwastrel

I've been writing about technology for most of my adult life, focusing mainly on legal and regulatory issues. I write for a wide range of publications: credits include the Times, Daily Telegraph and Financial Times newspapers, as well as BBC radio and numerous technology titles.

A hacking group that may be Russia -backed has been targeting Russia n and Belarusian non-profit organizations, Russia n independent media, international NGOs and at least one former U.S. ambassador. Access Now , the Citizen Lab at the University of Toronto, First Department, Arjuna Team, and Resident.

ngo, said they have uncovered at least two separate spear-phishing campaigns. One, they attribute to a known Russian threat group called Coldriver, also known as Star Blizzard or Callisto, and thought to be linked to the Russian government. The other, they believe, comes from a previously-unnamed group that they have dubbed 'Coldwastrel'.kicked off in March last year when Access Now was alerted by Russian human rights organization First Department to a phishing email that had been received by several international NGOs. The sender impersonated a staff member using the Proton Mail platform. Other similar alerts followed. The most common attack pattern involved a carefully-tailored email sent either from a compromised account or from an account appearing similar to the real account of someone the victim may have known. The emails were personalized to reflect the recipients' day-to-day work, mentioning topics such as event planning or financial discussions. The attacks also typically included a seemingly locked PDF attachment, sometimes with a link purporting to help 'unlock' the PDF’s content, but which in fact led to fake login pages aimed at harvesting the target’s information.Why Fans Think ‘It Ends With Us’ Stars Blake Lively, Justin Baldoni Are Feuding—As Baldoni Reportedly Hires Crisis PRAnd, said Access Now,"While investigating the attacks, we discovered that an IP address used by the attacker was linked to domains impersonating several prominent civil society organizations active in Eastern Europe." While some targets resisted falling for the scam, others were fooled into entering their user credentials, meaning it's likely that attackers were able to gain unauthorized access to their email accounts. "If successful, such attacks could be enormously harmful, particularly to Russian and Belarusian organizations and independent media, since their email accounts are likely to contain sensitive information about their staff’s identities, activities, relationships, and whereabouts," said Access Now. "Any contact between Russian NGOs or independent media with Western-based organizations could be used as a pretext by the Russian government to designate them as a 'foreign agent' or 'undesirable organization'.Most of the targets have chosen to remain anonymous. However, they include prominent Russian opposition figures-in-exile, staff at non-governmental organizations in the US and Europe, funders, and media organizations. There's a focus on Russia, Ukraine, or Belarus in all the cases. One target was Polina Machold, publisher of Proekt Media, which conducts high profile investigative reporting into official corruption and abuses of power in Russia. Another was former U.S. ambassador to Ukraine, Steven Pifer, who was targeted with a highly-credible approach impersonating someone known to him—a fellow former U.S. ambassador. "We judge that these targets may have been selected for their extensive networks among sensitive communities, such as high-risk individuals within Russia," said Access Now. "Importantly, we suspect that the total pool of targets is likely much larger than the civil society groups whose cases we have analyzed. We have observed US government personnel impersonated as part of this campaign, and given prior reporting about Coldriver'’s targeting, we expect the US government remains a target."from cybersecurity bodies in the U.S and several other countries, which identified it as a subordinate of the Russian Federal Security Service’s Centre 18.Our community is about connecting people through open and thoughtful conversations. We want our readers to share their views and exchange ideas and facts in a safe space.Insults, profanity, incoherent, obscene or inflammatory language or threats of any kindContinuous attempts to re-post comments that have been previously moderated/rejectedAttempts or tactics that put the site security at riskProtect your community.

We have summarized this news so that you can read it quickly. If you are interested in the news, you can read the full text here. Read more:

ForbesTech /  🏆 318. in US

Citizen Labs Coldriver Coldwastrel Spear-Phishing Russia

 

United States Latest News, United States Headlines

Similar News:You can also read news stories similar to this one that we have collected from other news sources.

How Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep WinterHow Russia-Linked Malware Cut Heat to 600 Ukrainian Buildings in Deep WinterThe code, the first of its kind, was used to sabotage a heating utility in Lviv at the coldest point in the year—what appears to be yet another innovation in Russia’s torment of Ukrainian civilians.
Read more »

Ukrainian troops roll into Russia in major cross-border attackUkrainian troops roll into Russia in major cross-border attackRussia claims to fire on Ukrainian forces moving into Russia’s Kursk region
Read more »

Veteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesVeteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesA human rights activist since the 1980s, Oleg Orlov thought Russia had turned a corner when the Soviet Union collapsed and a democratically elected president became leader.
Read more »

Veteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesVeteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesA human rights activist since the 1980s, Oleg Orlov thought Russia had turned a corner when the Soviet Union collapsed and a democratically elected president became leader. But then Vladimir Putin rose to power, crushing dissent and launching a full-scale invasion of Ukraine.
Read more »

Veteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesVeteran human rights advocate freed in swap says Russia is sliding back toward Stalinist timesA human rights activist since the 1980s, Oleg Orlov thought Russia had turned a corner when the Soviet Union collapsed and a democratically elected president became leader.
Read more »

Russia Declares Emergency in Region Invaded by Ukraine as Zelensky Says Russia Needs to ‘Feel’ WarRussia Declares Emergency in Region Invaded by Ukraine as Zelensky Says Russia Needs to ‘Feel’ WarSource of breaking news and analysis, insightful commentary and original reporting, curated and written specifically for the new generation of independent and conservative thinkers.
Read more »



Render Time: 2026-05-26 19:25:07