Google has uncovered a new piece of malware called LOSTKEYS, attributed to the Russian government-backed threat group Cold River (also known as UNC4057, Star Blizzard, and Callisto). The group is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker. LOSTKEYS marks a new development in the toolset of Cold River, a group primarily known for credential phishing against high-profile targets like NATO governments, non-governmental organizations (NGOs), and former intelligence and diplomatic officers.
More info can be found here. https://cloud.google.com/blog/topics/threat-intelligence/coldriver-steal-documents-western-targets-ngos
Erich Kron, security awareness advocate at cybersecurity firm KnowBe4, commented:
“There can be no doubt that intelligence gathering and cyber warfare is taking place at the nation-state level and will probably do so for the foreseeable future. This is simply the digital version of a spy sneaking in a micro camera and taking pictures of sensitive information and then providing it to whomever they work for. While these attacks are targeting mostly non-governmental organizations (NGOs), many of them do have ties to government agencies and could have information useful to that government’s adversaries.
“Because it seems they prefer tactics such as social engineering through email phishing, organizations should ensure that they have a well implemented human risk management (HRM) program in place that includes training and education to help employees fend off social engineering attacks.”
The human element is always the weakest point. Thus improving that would go a long way in terms of heading off attacks.
UPDATE: Another comment has come in from Darren Siegel, Lead Sales Engineer at Outpost24:
“This is yet another example showing that credential theft is an ongoing area of risk, as even the strongest passwords can be captured by this kind of malware attack. While obviously the ideal outcome here would be to prevent such attacks from occurring in the first place, it underscores the need for organizations to implement continuous monitoring for compromised credentials, ideally using tools that are informed by threat intelligence that can quickly identify and respond to new breaches.”
Google Issues A Warning About A Threat Actor Going After Salesforce Data
Posted in Commentary with tags Google, Salesforce on June 4, 2025 by itnerdThreat actor “UNC6040” is impersonating IT support personnel at organizations via vishing (voice phishing) attacks to trick employees into granting them access to sensitive credentials, ultimately facilitating the theft of an organization’s Salesforce data.
Google has put out a warning about this which you can read here: https://cloud.google.com/blog/topics/threat-intelligence/voice-phishing-data-extortion
James McQuiggan, security awareness advocate at KnowBe4, commented:
“You wouldn’t blindly open your front door to a stranger, so we must consider whether you should pick up the phone and trust the voice on the other end.
Ask yourself: Were you expecting this call?
“Think about it. If someone knocked at your door and you weren’t expecting anyone, would you swing it open? Probably not. Most of us would peek through the window, check the camera, or at least ask, “Who is it?” The phone shouldn’t be any different. If you weren’t expecting a call from your IT support team, cloud service provider, or a software vendor, don’t assume the call is real. Cybercriminals are banking on that assumption. They’re hoping you’ll pick up the phone and follow instructions without pausing to think. If you do pick up, always verify. Sometimes, we do answer the door. The same goes for the phone. But once the conversation starts, stay skeptical. If the caller says they’re from a tech company and need access to your system, pause. Ask for their name, case number, and callback number. Then, hang up. Go to the company’s official support page or contact your tech team using another communication method. Contact them directly. See if there’s a case with your name on it. Assuredly, there isn’t.
Remember: legitimate tech companies don’t call you to fix an issue with your computer or application. That’s not how it works.
“There’s often a moment of hesitation. You don’t want to seem rude. You think, “What if this is real?” But being polite shouldn’t cost you your security when it comes to your data and username or password. Hanging up isn’t rude. It’s responsible.
Treat unexpected phone calls like you treat an unexpected knock at your door. Stop. Look. Verify. And if something feels off, it probably is. Stay cautious. Stay curious. And remember, security starts with a simple question: “Do I know who’s calling?”
Any organization that uses Salesforce should heed Google’s warnings and take action to educate their users so that they are not victims of this campaign. And I think it’s safe to say that we’ll be seeing more of this type of campaign going forward as threat actors wouldn’t do this if it were not effective.
Leave a comment »