Search

Emerging Cyber Threat: The LostKeys Spyware

11 May 2025

Google recently reported (via Android Headlines) the discovery of a new Russian spyware known as LostKeys, used by the hacker group ColdRiver, which is linked to the Russian FSB. This software is designed for stealing files and system data from Western organizations.

According to the Google Threat Intelligence Group (GTIG), LostKeys is employed in specialized ClickFix attacks that rely on social engineering, starting with a fake captcha. Victims are tricked into executing malicious PowerShell scripts that pave the way for downloading and running additional malware. The primary objective is to install LostKeys, which operates like a digital vacuum, extracting files, directories, and system information. Hackers also deploy other malware, including SPICA, to access documents.

The ColdRiver group has been active since 2017 and is known by other names such as Star Blizzard and Callisto Group. Reports indicate that it has ramped up its activities in recent years, particularly following Russia's invasion of Ukraine. The group specializes in cyber espionage, targeting government and defense institutions, think tanks, politicians, journalists, and NGOs.

The United States has already imposed sanctions on certain members of the group and announced a reward of $10 million for information leading to their capture.

Google experts emphasize the need to strengthen cybersecurity, especially for organizations that could become potential targets of ColdRiver attacks. They recommend utilizing Google’s advanced protection and regularly updating security systems to prevent such threats.