Cold River

Last Updated

Also known as: Nahr Elbard, Nahr el bared, Cold River, Callisto, TA446, SEABORGIUM, Calisto, TAG-53, COLDRIVER

In short, β€œCold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control traffic in combination with complex and convincing lure documents and custom implants.

🌍 Country Russia
πŸ“ Last Updated

Introduction

In short, β€œCold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control traffic in combination with complex and convincing lure documents and custom implants.

Activities and Tactics

Country of Origin: πŸ‡·πŸ‡Ί Russia

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

Information pending cataloguing.

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

Russian APT Tool Matrix observations

Category Observed tools
OffSec EvilGinx

Attribution and Evidence

Country of Origin: Russia Additional attribution information pending cataloguing.

References

References pending cataloguing.