216.73.216.226

Updates Arsenal with BAITSWITCH and SIMPLEFIX

· Published 24/09/2025 15:56 · Modified 24/09/2025 20:07

Export JSON

Essential information

Published
24/09/2025 15:56
Modified
24/09/2025 20:07
Tags
2025-09-24 apt backdoor baitswitch clickfix powershell russia simplefix social engineering
Related entities
1 intrusion sets (apt), 3 others

Description

A new multi-stage campaign, attributed to the -linked group COLDRIVER, has been discovered targeting Russian civil society members. The campaign employs techniques to trick users into executing malicious commands, leading to the deployment of two new malware families: (a downloader) and (a -based ). The attack chain involves a fake Cloudflare Turnstile checkbox, persistence establishment, and data exfiltration. COLDRIVER's tactics include using server-side checks, obfuscation techniques, and targeting specific file types for intelligence collection. The group's focus on NGOs, human rights defenders, and Russian exiles aligns with their known victimology.

External references