In a newly observed campaign, the Russia-linked advanced persistent threat (APT) group COLDRIVER has deployed a multi-stage malware strategy leveraging two lightweight tools — BAITSWITCH (a downloader) and SIMPLEFIX (a PowerShell backdoor) — to infiltrate systems across sectors. The campaign was detected by Zscaler’s ThreatLabz team, which tied it to the broader “ClickFix” exploitation technique.

COLDRIVER (also known by aliases such as Callisto, Star Blizzard, and UNC4057) has expanded its attack portfolio beyond spear-phishing and credential harvesting, incorporating customized toolsets like SPICA and LOSTKEYS to enhance its operational capabilities. The latest intrusion chain proceeds as follows:

  1. Victims are lured to fake CAPTCHA verification sites, tricked into running a malicious DLL via the Windows Run dialog.
  2. That DLL, BAITSWITCH, fetches SIMPLEFIX from attacker-controlled domains (e.g. “captchanom[.]top”).
  3. The campaign hides its tracks by erasing recent Run dialog entries, storing encrypted payloads in the Windows Registry, and deploying a PowerShell stager that contacts a secondary domain (“southprovesolutions[.]com”) to finalize the backdoor install.
  4. Once active, SIMPLEFIX orchestrates PowerShell commands, scripts, binaries, and data exfiltration through its command-and-control (C2) infrastructure.

Targeted files include documents across user directories, and overlap in victimology with earlier LOSTKEYS campaigns reinforces COLDRIVER’s continuity in tool evolution.

Coordinated Threats: BO Team and Bearlyfy in the Mix

This emerging COLDRIVER campaign coincides with intensified activity by two other groups: BO Team (aka Black Owl, Hoody Hyena) and Bearlyfy, both striking Russian entities.

  • BO Team: Observed by Kaspersky in September 2025, BO Team is utilizing password-protected RAR archives to deploy an updated BrockenDoor (in C#) and ZeronetKit (written in Go). ZeronetKit enables remote access, file transfers, command execution, and tunneling, while BrockenDoor enables persistence by installing payloads at system startup.
  • Bearlyfy: Active since early 2025, this group has employed ransomware strains such as LockBit 3.0 and Babuk in escalating attacks on Russian organizations. F6 researchers note that Bearlyfy’s operational model emphasizes swift, impactful attacks rather than sprawling, long-term campaigns.
  • In one incident targeting a consulting firm, the attackers exploited a vulnerable Bitrix installation and leveraged the Zerologon flaw for privilege escalation — eventually demanding €80,000 in cryptocurrency.

Of note, Bearlyfy shares infrastructure overlap with PhantomCore — a pro-Ukrainian actor known to target Russian interests since 2022 — though analysts treat it as a distinct entity.

Why It Matters: Escalation in Russian-Focused Cyber Warfare

The use of ClickFix-style tactics by COLDRIVER suggests that deceptive techniques remain effective, even without high technical novelty. “The continued use of ClickFix suggests it is an effective infection vector, even if it is neither novel nor technically advanced,” said Zscaler’s Sudeep Singh and Yin Hong Chang.

COLDRIVER’s historical focus includes NGOs, human rights defenders, think tanks, and exiled Russian dissidents — indicating that the group’s latest campaigns likely continue that pattern of politically motivated targeting.

Meanwhile, the simultaneous activity of BO Team and Bearlyfy underscores how Russia itself may now be becoming a battleground in cyber conflict. Rather than exclusively targeting external nations, APTs are turning their tools inward, refining tactics for local adversaries. Defensive readiness in Russian sectors — and those interfacing with them — faces a new challenge.

From a defensive posture perspective, organizations can take heed:

  • Deploy endpoint protections that can inspect and block suspicious DLL execution, PowerShell usage, or unauthorized registry operations.
  • Use network monitoring and anomaly detection for unusual HTTP or C2-like traffic patterns.
  • Audit external file-access systems (e.g. Bitrix) and patch vulnerabilities such as Zerologon.
  • Promote user security awareness around verification prompts and CAPTCHA-like deceptions.

Conclusion

The newly revealed COLDRIVER campaign — introducing BAITSWITCH and SIMPLEFIX — marks a tactical evolution for a long-running Russia-linked actor. Its coordination (or concurrent activity) alongside BO Team and Bearlyfy highlights a more complex cyber threat landscape focused on Russia itself. As threat groups sharpen their tools and strategy, defenders must evolve rapidly to detect and disrupt the infection chains before they gain a foothold.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *