A Russian hacker group tracked as Cold River APT targeted three nuclear research centers in the U.S. in 2022. The campaigns happened between August and September.
More:
- The Cold River APT group targeted the Brookhaven, Argonne, and Lawrence Livermore national laboratories.
- The hacker group created fake log-in pages and sent them to nuclear scientists, attempting to steal their credentials through phishing.
- Neither representatives from the laboratories nor security researchers have been able to confirm if the hacking campaign was successful and, if so, what data was stolen.
- Also known as Calisto, Cold River APT has become increasingly more active ever since the war in Ukraine began in February 2022.
- The threat actor has attacked NATO, U.S. NGOs, Ukrainian defense contractors, etc.
















