Ethical Hacking News
A new and highly sophisticated malware campaign has emerged, attributed to the Russian advanced persistent threat (APT) group known as COLDRIVER, which has joined forces with BO Team and Bearlyfy to deliver a series of targeted cyberattacks in Russia. The campaign features two "lightweight" malware families tracked as BAITSWITCH and SIMPLEFIX, both of which have been linked to significant technical sophistication and organizational complexity. As the threat landscape continues to evolve, it is essential for cybersecurity professionals and policymakers alike to stay informed about emerging threats and develop effective countermeasures to mitigate their impact.
The Russian advanced persistent threat (APT) group COLDRIVER has emerged with a new malware campaign, attributed to the ClickFix tactics.The campaign features two "lightweight" malware families: BAITSWITCH and SIMPLEFIX, which are tracked as a downloader and PowerShell backdoor, respectively.COLDRIVER has joined forces with BO Team and Bearlyfy to deliver targeted cyberattacks in Russia.The attacks aim to trick unsuspecting users into running malicious DLLs, delivering payloads and establishing persistence on the victim's system.The use of ClickFix tactics highlights the continued evolution of cyber threats in Russia and underscores the need for sustained vigilance from cybersecurity professionals and policymakers.
Recently, a new and highly sophisticated malware campaign has emerged, one that showcases the continued evolution of cyber threats in the region. The campaign, attributed to the Russian advanced persistent threat (APT) group known as COLDRIVER, has been linked to two other prominent groups: BO Team and Bearlyfy.
According to recent reports from Zscaler ThreatLabz, the new multi-stage ClickFix campaign features two "lightweight" malware families tracked as BAITSWITCH and SIMPLEFIX. The BAITSWITCH family is described as a downloader that ultimately drops the SIMPLEFIX, a PowerShell backdoor. This development marks another significant entry in the arsenal of COLDRIVER, an APT group known for its technical sophistication and targeted attacks on various sectors since 2019.
The adversary's use of ClickFix tactics was previously documented by the Google Threat Intelligence Group (GTIG) back in May 2025, using fake sites serving fake CAPTCHA verification prompts to trick the victim into executing a PowerShell command that delivers the LOSTKEYS Visual Basic Script. The continued use of this infection vector is seen as an effective approach, even if it is neither novel nor technically advanced.
The latest attack chain follows the same modus operandi, tricking unsuspecting users into running a malicious DLL in the Windows Run dialog under the guise of completing a CAPTCHA check. This DLL, BAITSWITCH, reaches out to an attacker-controlled domain ("captchanom[.]top") to fetch the SIMPLEFIX backdoor, while a decoy document hosted on Google Drive is presented to the victims.
It also makes several HTTP requests to the same server to send system information, receive commands to establish persistence, store encrypted payloads in the Windows Registry, download a PowerShell stager, clear the most recent command executed in the Run dialog, effectively erasing traces of the ClickFix attack that triggered the infection. The downloaded PowerShell stager subsequently reaches out to an external server ("southprovesolutions[.]com") to download SIMPLEFIX, which, in turn, establishes communication with a command-and-control (C2) server to run PowerShell scripts, commands, and binaries hosted on remote URLs.
The emergence of this new campaign marks a significant development in the ongoing cat-and-mouse game between cybersecurity professionals and advanced threat actors. The involvement of COLDRIVER, BO Team, and Bearlyfy underscores the continued sophistication and organizational complexity of these groups, as well as their ability to target a wide range of sectors with varying degrees of success.
BO Team and Bearlyfy have also been linked to significant cyberattacks in Russia, targeting companies for ransom. The attacks are characterized by the use of custom tools such as SPICA and LOSTKEYS, which underscores the technical sophistication of these groups. The collaboration between COLDRIVER, BO Team, and Bearlyfy may indicate a growing trend towards collaborative threat operations among Russian-speaking APT groups.
The continued evolution of cyber threats in Russia highlights the need for sustained vigilance from cybersecurity professionals and policymakers alike. As we move forward into an increasingly complex and dynamic cybersecurity landscape, it is essential to stay informed about emerging threats and develop effective countermeasures to mitigate their impact.
In recent months, there have been numerous reports of Russian-speaking APT groups targeting various sectors, including NGOs, human rights defenders, think tanks in Western regions, as well as individuals exiled from and residing in Russia. The focus of these campaigns closely aligns with the victimology of these groups, which target members of civil society connected to Russia.
As we look at this new development in light of previous reports on Russian-speaking APT groups, it becomes increasingly clear that the cyber threat landscape is becoming more complex, sophisticated, and collaborative by the day. The emergence of COLDRIVER, BO Team, and Bearlyfy underscores the need for effective countermeasures to be developed and implemented at both the individual and organizational levels.
In conclusion, the recent emergence of a new COLDRIVER malware campaign that has joined forces with BO Team and Bearlyfy to deliver Russia-focused cyberattacks highlights the continued evolution of advanced threat actors in the region. As we move forward into this complex and dynamic landscape, it is essential to stay informed about emerging threats and develop effective countermeasures to mitigate their impact.
A new and highly sophisticated malware campaign has emerged, attributed to the Russian advanced persistent threat (APT) group known as COLDRIVER, which has joined forces with BO Team and Bearlyfy to deliver a series of targeted cyberattacks in Russia. The campaign features two "lightweight" malware families tracked as BAITSWITCH and SIMPLEFIX, both of which have been linked to significant technical sophistication and organizational complexity. As the threat landscape continues to evolve, it is essential for cybersecurity professionals and policymakers alike to stay informed about emerging threats and develop effective countermeasures to mitigate their impact.
Related Information:
https://www.ethicalhackingnews.com/articles/New-COLDRIVER-Malware-Campaign-Joins-Forces-with-BO-Team-and-Bearlyfy-to-Deliver-Russia-Focused-Cyberattacks-ehn.shtml
https://thehackernews.com/2025/09/new-coldriver-malware-campaign-joins-bo.html
https://tech-wire.in/technology/cyber-security/new-coldriver-malware-campaign-joins-bo-team-and-bearlyfy-in-russia-focused-cyberattacks/
https://www.zscaler.com/blogs/security-research/coldriver-updates-arsenal-baitswitch-and-simplefix
https://cloud.google.com/blog/topics/threat-intelligence/coldriver-steal-documents-western-targets-ngos
https://cybersecsentinel.com/lostkeys-malware-campaign-traced-to-cold-river-threat-group/
https://www.pcrisk.com/removal-guides/28826-spica-backdoor
https://attack.mitre.org/software/S1140/
https://gbhackers.com/coldriver-apt-group/
https://cybermaterial.com/bo_team-bo-team-threat-actor/
Published: Sat Sep 27 00:41:59 2025 by llama3.2 3B Q4_K_M