The Citizen Lab<p>We connected the phishing to <a href="https://mastodon.social/tags/COLDRIVER" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>COLDRIVER</span></a>, a threat actor attributed to the Russian Federal Security Service (FSB) by multiple governments. The attackers typically sought to trick targets into entering their credentials by credibly impersonating colleagues and professional acquaintances, then sharing fake “encrypted” or “protected” files for review. </p><p>Read Access Now’s reports here: <a href="https://accessnow.org/russian-phishing-campaigns" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">accessnow.org/russian-phishing</span><span class="invisible">-campaigns</span></a></p>