Google: LOSTKEYS Malware Escalates Russian Cyber Threat
Google: LOSTKEYS Malware Escalates Russian Cyber Threat

Google: LOSTKEYS Malware Escalates Russian Cyber Threat

News summary

Google's Threat Intelligence Group has identified a new malware strain, LOSTKEYS, deployed by the Russian state-backed hacking group Cold River—also known as Star Blizzard, Callisto, and Seaborgium—which is linked to Russia's FSB. Since early 2025, LOSTKEYS has been used in targeted espionage campaigns against Western governments, advisers, journalists, NGOs, think tanks, and individuals associated with Ukraine. The malware is delivered via the ClickFix social engineering technique, tricking users into running malicious PowerShell scripts that enable attackers to steal files, system information, and credentials. These campaigns represent an escalation in Cold River's operations, moving from credential theft to direct data exfiltration for Russian intelligence. Past Cold River targets include NATO governments and U.S. nuclear research labs. Google recommends heightened vigilance and least-privilege policies to counter these threats.

Story Coverage
Bias Distribution
50% Left
Information Sources
0de89078-8bc1-4dae-b16e-c0e6d67fee74bfb2a97b-336e-48d9-b69a-147df7862dc2a3544a73-dab3-486d-ae75-bd4d15f01f55538ad27c-7e41-4215-a5e1-3c6c21cfd9ff
Left 50%
Center 25%
Right 25%
Coverage Details
Total News Sources
4
Left
2
Center
1
Right
1
Unrated
0
Last Updated
22 days ago
Bias Distribution
50% Left
Related News
Daily Index

Negative

22Serious

Neutral

Optimistic

Positive

Ask VT AI
Story Coverage
Subscribe

Stay in the know

Get the latest news, exclusive insights, and curated content delivered straight to your inbox.

Present

Gift Subscriptions

The perfect gift for understanding
news from all angles.

Related News
Recommended News