logo

Spear-phishing cases from Eastern Europe in 2022-2023 and 2024: a technical brief

ID: 1769a2e5-aef9-49cd-b001-823eac816004

STIX ID: report--1769a2e5-aef9-49cd-b001-823eac816004

Threat Score

75/100

Uploaded: 2026-08-11

Published Date: 2024-08-14

Last Modified Date: 2024-08-14

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Access Now technical brief analyzes two spear-phishing campaigns (COLDWASTREL and COLDRIVER) active from 2022–2024 targeting Eastern European civil society and NGOs. The attackers used lookalike ProtonMail addresses, seemingly locked PDF attachments containing links to fake login pages or staged validation flows, and hosted infrastructure on VPS providers; the report includes IOCs (domains, IPs, PDF hashes), metadata analysis, and mitigation recommendations for high-risk users.