Google Identifies Lostkeys, a Russian Malware That Can Steal Specific Files and Directories

As per Google, Lostkeys is a visual basic script (VBS) type data theft malware.

Advertisement
Written by Akash Dutta, Edited by Siddharth Suvarna | Updated: 12 May 2025 15:59 IST
Highlights
  • The malware is said to be linked to the Russian threat group Coldriver
  • Lostkeys malware was first observed in January
  • It is spread via a multi-step infection chain, starting with a lure site

Google has upgraded Chrome to protect users from websites that might be spreading this malware

Photo Credit: Reuters

Google Threat Intelligence Group (GTIG) shared a report about a new piece of malware last week. The new malware, dubbed Lostkeys, is described as a data theft malware and is said to be linked with the Russian threat group Coldriver. Lostkeys is considered dangerous because it is being spread at the end of a multi-step chain that starts with a lure website. The malware can steal specific files from a hard-coded list of extensions and directories. Additionally, it can also send system information and running processes to the attacker.

New Malware Linked to Russian Threat Group Coldriver Identified

In a blog post, the Mountain View-based tech giant highlighted that the newly discovered malware was first observed in January, followed by multiple observations in March and April. It appears to be the new tool in the arsenal of the threat group Coldriver (also known as UNC4057, Star Blizzard, and Callisto).

Advertisement

Notably, Google highlights that Coldriver is known for running credential phishing against targets such as NATO governments, non-governmental organisations (NGOs), as well as militaries, journalists, and diplomatic officers. The group was associated with the Spica malware in 2024.

The modus operandi (MO) of the group is trickier than typical phishing attacks. First, fake emails impersonating legitimate institutions are shared with victims. These emails contain website links. These are lure websites that feature fake CAPTCHA to convince the victim of their legitimacy. When the user confirms the CAPTCHA, PowerShell is copied to the user's clipboard.

Advertisement

Notably, PowerShell is a command-line shell and scripting language primarily used for system administration, automation, and configuration management in Windows environments. Because PowerShell is built into Windows and has deep system access, it's often abused by attackers to download and execute malware in memory.

Once the PowerShell has been copied, the page prompts the user to execute it via the “run” prompt. Once the user has done that, it triggers the second stage, which is focused on calculating the MD5 hash of the display resolution of the device. It is typically followed by a third stage to evade execution in virtual machines (in case it did not detect MD5 in the second step).

Advertisement

After this, another code execution retrieves and decodes the final payload, which is a visual basic script (VBS) file, otherwise known as Lostkeys. GTIG highlights that it is capable of “stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker.”

Google states that Coldriver typically uses malware to steal emails and contacts from targets; however, at times, it is also known to deploy malware such as Spica to access documents on the target system. Lostkeys also enables a similar goal.

Advertisement

Notably, the tech giant has added all the identified malicious websites, domains, and files to Safe Browsing in Google Chrome to protect users from exploitation. Additionally, it is also sending government-backed attacker alerts to targeted Gmail and Workspace users. These alerts notify users about the threat and encourage them to enable Enhanced Safe Browsing.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Nothing Phone 4a Pro Review: A Big Leap
  2. Samsung Will Launch New Galaxy A-Series Smartphones in India on This Date
  3. OTT Releases This Week: Border 2, Peaky Blinders: The Immortal Man, Chiraiya, and More
  4. Here's When the Redmi 15A 5G Will Be Launched in India
  5. Oppo K14 5G With 7,000mAh Battery Goes on Sale in India: See Price, Offers
  6. OnePlus 15T Camera Features Teased Ahead of March 24 Launch
  7. Xiaomi Unveils SU7 Facelift With Nvidia Thor-Powered Assisted Driving
  8. Google Announces New Sideloading Rules for Android
  9. Realme 16 5G Will Finally Launch in India Soon, Tipster Claims
  10. Boat Valour Watch 1R With Up to 10-Day Battery Life Launched in India
  1. Carl Pei Says ‘Apps Are Going to Disappear’ as Smartphones Become More Agentic
  2. Realme 16 5G Tipped to Launch in India Soon; Expected Price, Specifications
  3. MLB Inks Deal With Polymarket, US CFTC to Build Prediction Market Framework
  4. Huawei MatePad 11.5, MatePad SE 11 Full Specifications List Revealed via Flipkart Listings
  5. Boat Valour Watch 1R Launched in India With 1.43-Inch AMOLED Display, Up to 10-Day Battery Life: Price, Features
  6. Xiaomi SU7 EV Refreshed With 902km CLTC Range, Nvidia Thor AGX-Powered Assisted Driving Features
  7. Samsung Sets March 25 Launch Date for New Galaxy A-Series in India; Galaxy A37, Galaxy A57 Design Tipped Again
  8. Anthropic Study Finds People Don’t Really Want AI for Creative Work
  9. Bitcoin Trades Near $71,000 as Crypto Market Weathers Ongoing Macroeconomic Pressures
  10. Redmi 15A 5G India Launch Date Announced; Design and Specifications Teased
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.