logo

COLDRIVER Adds BAITSWITCH and SIMPLEFIX

ID: 4a1c0b6f-a55e-507f-b0dd-f31fbae597e3

STIX ID: report--4a1c0b6f-a55e-507f-b0dd-f31fbae597e3

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-09-24

Date Updated: 2026-05-01

...
...

Executive summary: This report analyzes a targeted multi-stage campaign that lures victims via a fake Cloudflare Turnstile (ClickFix) page which tricks users into running a malicious rundll32 command to load a downloader DLL (BAITSWITCH). BAITSWITCH establishes persistence, stores encrypted payloads in the registry, retrieves a PowerShell stager and ultimately deploys the SIMPLEFIX PowerShell backdoor from actor-controlled domains (notably captchanom.top and southprovesolutions.com). The backdoor performs reconnaissance, supports remote binary execution and PowerShell execution, and exfiltrates file listings and command output; the campaign uses registry-based persistence, RunMRU cleanup, hardcoded user-agent/C2 checks, and decoy documents to blend activity and target Russian civil society actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.