COLDRIVER Adds BAITSWITCH and SIMPLEFIX
ID: 4a1c0b6f-a55e-507f-b0dd-f31fbae597e3
STIX ID: report--4a1c0b6f-a55e-507f-b0dd-f31fbae597e3
Feed Name: Zscaler Security Research Blog
Executive summary: This report analyzes a targeted multi-stage campaign that lures victims via a fake Cloudflare Turnstile (ClickFix) page which tricks users into running a malicious rundll32 command to load a downloader DLL (BAITSWITCH). BAITSWITCH establishes persistence, stores encrypted payloads in the registry, retrieves a PowerShell stager and ultimately deploys the SIMPLEFIX PowerShell backdoor from actor-controlled domains (notably captchanom.top and southprovesolutions.com). The backdoor performs reconnaissance, supports remote binary execution and PowerShell execution, and exfiltrates file listings and command output; the campaign uses registry-based persistence, RunMRU cleanup, hardcoded user-agent/C2 checks, and decoy documents to blend activity and target Russian civil society actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
