Skip to content

Spica

SPICA is a custom malware backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, TA446, Blue Callisto, Blue Charlie, UNC4057, and IRON FRONTIER.

Profile source: Mallory opens in a new tab

Spica

Family profile

SPICA is a custom malware backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, TA446, Blue Callisto, Blue Charlie, UNC4057, and IRON FRONTIER. Google Threat Analysis Group reported in January 2024 that SPICA was the first known case of COLDRIVER developing and deploying custom malware. The malware has been used selectively against specific high-value individuals as part of COLDRIVER espionage activity, including efforts to access documents stored on compromised systems. Reported capabilities include persistence via an obfuscated PowerShell command that creates a scheduled task named CalendarChecker, cookie theft from Chrome, Firefox, Opera, and Edge, command-and-control communications over JSON via WebSockets, and archiving collected documents for exfiltration. Supporting content characterizes SPICA as a data-theft-oriented backdoor and notes it as a predecessor to COLDRIVER’s later LOSTKEYS malware. The broader actor has historically targeted civil society, NGOs, journalists, think tanks, government-related individuals, and Russian opposition-linked communities, particularly those connected to Russia, Ukraine, and Belarus. No additional high-confidence indicators of compromise beyond the CalendarChecker scheduled task name are directly provided in the content.

Reported operators

Threat actors

2 named in public reporting
Star Blizzard

In January of 2024, Google’s Threat Analysis Group (TAG) reported on a custom malware backdoor called SPICA, which they assessed was the first known case of COLDRIVER developing and deploying custom malware.

MITRE ATT&CK

Spica in ATT&CK

14 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.