COLDRIVER’s Sophisticated LOSTKEYS Malware Targets Western Entities

Google Threat Intelligence recently exposed COLDRIVER, a threat group leveraging new malware, LOSTKEYS, to infiltrate Western organizations. This marks a significant evolution from their previous credential phishing tactics.
The four-stage attack begins with a deceptive website featuring a fake CAPTCHA. A PowerShell script is covertly downloaded to the victim’s clipboard, evading security measures before delivering the final payload and installing the malware. This sophisticated method underscores the group’s increasing capabilities.
LOSTKEYS excels at exfiltrating files from various extensions and directories, simultaneously transmitting system information and active processes back to the attackers. Google identified “165.227.148[.]68” as the source IP address.
Google has proactively mitigated the threat by adding malicious websites to its Safe Browsing feature. This highlights the importance of robust cybersecurity practices in the face of increasingly advanced cyberattacks.
COLDRIVER, allegedly backed by Russia, has a history of targeting high-profile Western individuals including former diplomats and journalists. Their previous malware, Spica (deployed in January 2024), enabled arbitrary shell commands and software downloads/uploads.
Related: Crypto drainers now sold as easy-to-use malware at IT industry fairs
Record Crypto Hack Losses in 2025
Cryptocurrency hacks have surged to unprecedented levels, with losses exceeding $2 billion in the first quarter of 2025—surpassing the total losses recorded for the entirety of 2024. According to Hacken, a leading cybersecurity firm, operational flaws and weak access controls continue to be major vulnerabilities, impacting both centralized and decentralized platforms.
Social engineering tactics remain a potent weapon for attackers. The $1.5 billion Bybit exchange hack in February, attributed to the Lazarus Group, significantly contributed to the alarming figures.
Magazine: Lazarus Group’s favorite exploit revealed — Crypto hacks analysis