CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines, daily updates. Fast, privacy‑respecting. No ads, no tracking.

COLDRIVER Campaign Delivers BAITSWITCH and SIMPLEFIX Malware

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

The Russian APT group COLDRIVER launched a new ClickFix-style campaign in September 2025, delivering two new malware families: BAITSWITCH and SIMPLEFIX. The campaign targets civil society members connected to Russia, including NGOs, human rights defenders, and think tanks. The attack chain tricks users into running a malicious DLL, leading to the deployment of SIMPLEFIX, a PowerShell backdoor. The malware exfiltrates information and establishes persistence on compromised systems. The development coincides with phishing campaigns by the BO Team and Bearlyfy, targeting Russian companies with new malware and ransomware strains.

Timeline

  1. 26.09.2025 15:45 1 articles · 2h ago

    COLDRIVER Launches New Campaign with BAITSWITCH and SIMPLEFIX Malware

    In September 2025, COLDRIVER initiated a new ClickFix-style campaign delivering BAITSWITCH and SIMPLEFIX malware. The campaign targets civil society members connected to Russia, using a malicious DLL to trick users into executing the malware. SIMPLEFIX establishes communication with a C2 server to exfiltrate information and maintain persistence. The development coincides with phishing campaigns by the BO Team and Bearlyfy targeting Russian companies.

    Show sources

Information Snippets