Spica

MITRE ATT&CK: S1140 View on attack.mitre.org

Aliases: Spica

First seen
2023-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Related IoCs
11 (7 malicious)
Last IoC activity
2026-08-06 13:52:36
Profile updated
2026-07-07 12:50:19

Targeted industries: government-and-public-sector technology-and-telecommunications

Context

Spica is a custom backdoor written in Rust that has been used by Star Blizzard since at least 2023.

Recent IoC activity

7 malicious indicators in Maltiverse are attributed to Spica (S1140). The 7 most recently updated:

TypeIndicatorUpdatedSources
hostname app.kefel.tech 2026-08-06 1
hostname kefel.io 2025-07-26 1
hostname s4.kefel.tech 2025-07-26 1
hostname kefel.tech 2025-07-26 1
hostname s3.kefel.tech 2025-07-26 1
hostname s2.kefel.tech 2025-07-26 1
hostname s1.kefel.tech 2025-07-26 1

Detection coverage

  • 1 YARA rules
  • 324 Sigma rules

Malware & tools used

  • PowerShell (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Steal Web Session Cookie (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Spica_Auto (yara-rule)

Reports & references

  • blog.google — Google Tag Coldriver Russian Phishing Malware (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Spica (report)
  • MITRE ATT&CK — S1140 (report)

External references