• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Tuesday, December 16, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

French NGO Reporters Without Borders Targeted by Star Blizzard

December 3, 2025
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


A contemporary wave of spear-phishing exercise linked to the Russia-nexus intrusion set Star Blizzard, often known as ColdRiver or Calisto, has been recognized by cybersecurity researchers.

The group has been lively since 2017 and is attributed by a number of Western governments to Russia’s FSB Heart 18.

In keeping with a brand new evaluation by Sekoia.io’s TDR crew, the most recent incidents have been reported in Might and June 2025 by two organizations, together with Reporters With out Borders (RSF), prompting a better have a look at how the operators refined their credential-harvesting strategies.

A Acquainted Intrusion Set Expands Its Focus

The brand new collection of phishing makes an attempt follows Star Blizzard’s long-running concentrate on Western entities backing Ukraine.

The group is understood for impersonating trusted contacts and prompting targets to request lacking or malfunctioning attachments. As soon as the sufferer requests the file, the attacker sends a second message containing a hyperlink to malware or a phishing web page.

In a single case involving RSF in March 2025, a ProtonMail deal with mimicking a legit contact despatched a French-language e-mail asking a core member to evaluate a doc. No file was hooked up.

When the member requested it, the operators replied in English with a hyperlink routed by means of a compromised web site to a ProtonDrive URL. Nevertheless, the file itself couldn’t be retrieved as a result of ProtonMail had blocked the related account.

Learn extra : Russian Coldriver Hackers Deploy New ‘NoRobot’ Malware

A second sufferer obtained a file labeled as a PDF that was really a ZIP archive disguised with a .pdf extension. The ultimate stage of the assault used a typical Calisto decoy PDF that claimed to be encrypted and instructed the consumer to open it in ProtonDrive. The hyperlink once more despatched the goal by means of a redirector hosted on a compromised web site.

Infrastructure Factors to Ongoing Exercise

The phishing package analyzed by TDR, situated on account.simpleasip[.]org, gave the impression to be customized constructed.

It focused ProtonMail accounts utilizing an Adversary-in-the-Center (AiTM) setup that relays two-factor authentication (2FA). Analysts discovered injected JavaScript designed to maintain the cursor locked to the password area and to work together with an attacker-controlled API for dealing with CAPTCHA and 2FA prompts.

Key observations included:

  • Modified ProtonMail interface components

  • Persistent password-field focus

  • API-based credential processing

Star Blizzard’s infrastructure included servers internet hosting phishing pages and others serving as API endpoints. Many domains have been tied to Namecheap providers, whereas some earlier ones have been registered through Regway to assist analysts monitor the cluster over time.

“Regardless of quite a few publications on this menace actor, Calisto continues its spear-phishing campaigns for credential harvesting or code execution through the ClickFix method,” Sekoia warned.

“We’re on the disposal of any NGO wishing to analyse and/or attribute assault campaigns to a cluster of exercise.”



Source link

Tags: BlizzardbordersFrenchNGOreportersstarTargeted
Next Post
Release candidates of iOS 26.2, macOS 26.2 now available

Release candidates of iOS 26.2, macOS 26.2 now available

Beirut, LB
28°
Partly Cloudy
06:2218:40 EEST
Feels like: 30°C
Wind: 11km/h SW
Humidity: 58%
Pressure: 1011.18mbar
UV index: 7
SatSunMon
30°C / 25°C
31°C / 26°C
31°C / 26°C
powered by Weather Atlas

Recent News

Below Deck Med Recap: Joe Hides Him Cheating on Victoria With Kizzi

Below Deck Med Recap: Joe Hides Him Cheating on Victoria With Kizzi

December 16, 2025
Who Is Claudio Gama? Meet the Husband of Late Actor Anthony Geary – Hollywood Life

Who Is Claudio Gama? Meet the Husband of Late Actor Anthony Geary – Hollywood Life

December 16, 2025
Ciara to Headline First TikTok Awards in the U.S.

Ciara to Headline First TikTok Awards in the U.S.

December 16, 2025
Trump Says He’ll Examine Case of Samourai Wallet Developer

Trump Says He’ll Examine Case of Samourai Wallet Developer

December 16, 2025
Bitcoin Price Drops 5%—Is the Downtrend Back in Control?

Bitcoin Price Drops 5%—Is the Downtrend Back in Control?

December 16, 2025
A 23-Year-Old Man Charged in  Million Coinbase “Customer-Care” Scam

A 23-Year-Old Man Charged in $15 Million Coinbase “Customer-Care” Scam

December 16, 2025
Crypto Market Drops As Trump Changes Fed Pick, AI Bubble Concerns Rise

Crypto Market Drops As Trump Changes Fed Pick, AI Bubble Concerns Rise

December 16, 2025
PAW Patrol Rescue Wheels: Championship Review

PAW Patrol Rescue Wheels: Championship Review

December 16, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

Below Deck Med Recap: Joe Hides Him Cheating on Victoria With Kizzi

Below Deck Med Recap: Joe Hides Him Cheating on Victoria With Kizzi

December 16, 2025
Who Is Claudio Gama? Meet the Husband of Late Actor Anthony Geary – Hollywood Life

Who Is Claudio Gama? Meet the Husband of Late Actor Anthony Geary – Hollywood Life

December 16, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.