Cold River

Aliases: Nahr Elbard, Nahr el bared

First seen
2017-07-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-18 22:23:36
Profile updated
2026-07-07 11:56:26

Targeted industries: government-and-public-sector technology-and-telecommunications energy-and-utilities media-and-entertainment

Context

In short, “Cold River” is a sophisticated threat (actor) that utilizes DNS subdomain hijacking, certificate spoofing, and covert tunneled command and control traffic in combination with complex and convincing lure documents and custom implants.

Reports & references

  • lastline.com — Threat Actor Cold River Network Traffic Analysis And A Deep Dive On Agent Drable (report)

External references