ClickFix-style assaults targeting two new “lightweight” malware families known as BAITSWITCH and SIMPLEFIX have been linked to the Russian advanced persistent threat (APT) group COLDRIVER.
The new multi-stage ClickFix campaign was discovered earlier this month by Zscaler ThreatLabz, which characterized BAITSWITCH as a downloader that eventually installs SIMPLEFIX, a PowerShell backdoor.
Since 2019, a Russian-affiliated threat actor known as COLDRIVER—also known as Callisto, Star Blizzard, and UNC4057—has been reported to attack a variety of industries. The gang has been expanding its toolkit with unique tools like SPICA and LOSTKEYS, which highlights its technological sophistication, even if early campaign waves were seen employing spear-phishing lures to guide targets to credential harvesting pages.
In May 2025, the Google Threat Intelligence Group (GTIG) first reported on the adversary’s use of ClickFix techniques, which involve tricking the victim into running a PowerShell command intended to deliver the LOSTKEYS Visual Basic Script by using phony websites read more about New COLDRIVER Malware Campaign Joins BO Team and Bearlyfy in Russia-Focused Cyberattacks.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
