Alert: Attack on Moldovan Civil Society and Media Organizations, Resembling Cold River's Tactics

Кибератака на молдавские СМИ и организации гражданского общества — кампания с признаками Cold River Important

The Digital Skills Coalition Belarus team wants to flag a finding from our colleagues at RESIDENT.NGO.

Cold River (also known as Star Blizzard), a hacking group linked to Russian state security services, has for years been known for attacking journalists, NGOs, and activists through fake emails impersonating familiar organizations. The RESIDENT.NGO team uncovered a campaign that closely resembles their tactics: in September 2026, attackers sent Moldovan media outlets and civil society organizations emails impersonating European donors, attempting to infect computers with malware. Researchers aren’t fully certain this is Cold River, but the techniques match almost exactly. Here’s what RESIDENT.NGO found and what to do if someone in our circle receives a similar email.

What to do if you receive a suspicious email

  • A legitimate donor never sends a proposal or invitation as a virtual disk file (.vhdx, .iso, .img extensions) or as a password-protected archive with the password written in the same email. This alone is a sign of an attack, don’t open such a file.
  • If an offer or invitation is unexpected, verify it through a channel you already know (for example, call the organization directly) before replying or opening anything.
  • If a suspicious file has already been opened on a Windows computer, disconnect the device from the network immediately (turn off Wi-Fi/unplug the cable) and contact a security specialist.

What RESIDENT.NGO found

It starts with an ordinary, friendly email: an invitation to a conference or a grant offer in the name of a real, well-known organization (in this case, European Business Summits, the European Endowment for Democracy, and East Europe Foundation Moldova). The sender’s name is familiar, but the email address is fake.

If the person replies and shows interest, they’re sent a password-protected archive (the password is given in the email itself). Inside is not an ordinary document but a virtual disk image file. Opening it shows a convincing PDF with the proposal, while in the background a malicious program is quietly installed: it contacts the attacker’s server and can download additional malicious modules at any time.

What makes this especially sneaky is that Windows’ usual warning about files downloaded from the internet may not trigger in this case, so nothing looks suspicious at a glance.

Read more

The full technical report from RESIDENT.NGO, with attack details, indicators of compromise, and screenshots, is published on their site:
👉 resident.ngo/lab/writeups/malware-campaign-impersonates-european-donors-to-target-moldovan-media-and-civil-society

Rate article
Digital Skills Coalition Belarus