{"id":667672,"date":"2025-05-07T22:03:35","date_gmt":"2025-05-07T19:03:35","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/coldriver-using-new-malware-to-steal-from-western-targets-google\/"},"modified":"2025-05-07T22:03:35","modified_gmt":"2025-05-07T19:03:35","slug":"coldriver-using-new-malware-to-steal-from-western-targets-google","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/coldriver-using-new-malware-to-steal-from-western-targets-google\/","title":{"rendered":"COLDRIVER using new malware to steal from Western targets \u2014 Google"},"content":{"rendered":"<p style=\"float:right;margin:0 0 10px 15px;width:240px\">\n                        <img decoding=\"async\" src=\"https:\/\/images.cointelegraph.com\/images\/840_aHR0cHM6Ly9zMy5jb2ludGVsZWdyYXBoLmNvbS91cGxvYWRzLzIwMjQtMTIvMDE5MzhjYWYtMDEwMC03MGRiLWFkZGYtZGJmMTkxODA2YzYz.jpg\" class=\"type:primaryImage\">\n                    <\/p>\n<p>The malware, LOSTKEYS, can steal files from hard-coded extensions and directories, according to Google.<\/p>\n<p><p>Threat group COLDRIVER is using new malware to steal documents from Western targets, <a rel=\"nofollow\" target=\"_blank\" data-ct-non-breakable=\"null\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/coldriver-steal-documents-western-targets-ngos\/\" rel=\"null\" target=\"null\" title=\"null\">according<\/a> to a May 7 report from Google Threat Intelligence. The malware, called LOSTKEYS, shows the evolution of the group from credential phishing to more sophisticated attacks.<\/p>\n<p>According to the Google report, the new malware is installed through four steps. The process involves a \u201clure website\u201d with a fake CAPTCHA, a PowerShell script <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">download<\/a>ed to the user\u2019s clipboard, some device evasion, and retrieval of the final payload. Lastly, the malware is installed.<\/p>\n<p>LOSTKEYS is capable of stealing files from extensions and directories. It can also send system information and running processes back to COLDRIVER. The address from which the parts of the attack come is \u201c165.227.148[.]68\u201d according to Google.<\/p>\n<p>Read more<\/p>\n<\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMN63nwsw68G3Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/category\/general\/\" target=\"_blank\" >General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/coldriver-new-malware-steal-western-targets-google?utm_source=rss_feed&#038;utm_medium=feed&#038;utm_campaign=rss_partner_inbound\" target=\"_blank\" >Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The malware, LOSTKEYS, can steal files from hard-coded extensions and directories, according to Google. Threat group COLDRIVER is using new malware to steal documents from Western targets, according to a May 7 report from Google Threat Intelligence. The malware, called LOSTKEYS, shows the evolution of the group from credential phishing to more sophisticated attacks. According&#8230;<\/p>\n","protected":false},"author":1,"featured_media":667673,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.cointelegraph.com\/cdn-cgi\/image\/format=auto,onerror=redirect,quality=90,width=1200\/https:\/\/s3.cointelegraph.com\/uploads\/2024-12\/01938caf-0100-70db-addf-dbf191806c63","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[75857,117,26293,4975],"class_list":["post-667672","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-malware","tag-business","tag-google","tag-russia"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/667672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=667672"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/667672\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/667673"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=667672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=667672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=667672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}