In January of 2024, Google’s Threat Analysis Group (TAG) reported on a custom malware backdoor called SPICA, which they assessed was the first known case of COLDRIVER developing and deploying custom malware.
Spica
SPICA is a custom malware backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, TA446, Blue Callisto, Blue Charlie, UNC4057, and IRON FRONTIER.
Profile source: Mallory opens in a new tabSpica
Family profile
SPICA is a custom malware backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, TA446, Blue Callisto, Blue Charlie, UNC4057, and IRON FRONTIER. Google Threat Analysis Group reported in January 2024 that SPICA was the first known case of COLDRIVER developing and deploying custom malware. The malware has been used selectively against specific high-value individuals as part of COLDRIVER espionage activity, including efforts to access documents stored on compromised systems. Reported capabilities include persistence via an obfuscated PowerShell command that creates a scheduled task named CalendarChecker, cookie theft from Chrome, Firefox, Opera, and Edge, command-and-control communications over JSON via WebSockets, and archiving collected documents for exfiltration. Supporting content characterizes SPICA as a data-theft-oriented backdoor and notes it as a predecessor to COLDRIVER’s later LOSTKEYS malware. The broader actor has historically targeted civil society, NGOs, journalists, think tanks, government-related individuals, and Russian opposition-linked communities, particularly those connected to Russia, Ukraine, and Belarus. No additional high-confidence indicators of compromise beyond the CalendarChecker scheduled task name are directly provided in the content.
Reported operators
Threat actors
2 named in public reportingTools Galileo RCS, Evilginx2, SPICA
MITRE ATT&CK