BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian APTs Launch New Malware Attacks; Bearlyfy Targets Firms

Russian-Linked COLDRIVER and Other Groups Deploy New Malware and Ransomware in Targeted Cyberattacks

  • Russian group COLDRIVER uses new Malware BAITSWITCH and SIMPLEFIX in recent attacks.
  • Attack methods include tricking users into running malicious files disguised as CAPTCHA prompts.
  • Victims include government, nonprofit, and civil society organizations with links to Russia.
  • Other groups, including BO Team and Bearlyfy, launched attacks against Russian companies with updated tools and Ransomware.
  • Ransom demands in recent attacks ranged from several thousand dollars to $86,000.

A recent cyberattack campaign by the Russian-linked group COLDRIVER, also known as Callisto, Star Blizzard, and UNC4057, targeted a range of organizations with new malware tools. The campaign, identified by Zscaler ThreatLabz in early June, uses a multi-stage method to deploy BAITSWITCH and SIMPLEFIX, described as lightweight downloaders and backdoors.

- Advertisement -

Researchers reported that BAITSWITCH acts by delivering SIMPLEFIX, a PowerShell-based backdoor. According to Zscaler, “The continued use of ClickFix suggests that it is an effective infection vector, even if it is neither novel nor technically advanced.” The attackers entice users with fake CAPTCHA prompts, which prompt them to run a malicious file. This file connects to an attacker-controlled internet domain to download the SIMPLEFIX malware. The malware sends device information, establishes remote access, and hides its tracks by clearing evidence from system logs.

Further analysis showed that SIMPLEFIX communicates with remote servers to run programs and collect files from targeted devices. The current campaign mimics the group’s previous operations, which typically aim at non-governmental organizations, activists, and others connected to Russian civil society.

In other developments, Cybersecurity firm Kaspersky identified a phishing attack against Russian companies by the group BO Team using password-protected archive files to distribute updated versions of BrockenDoor and a Golang-based backdoor called ZeronetKit. The ZeronetKit malware provides attackers with the ability to remotely control infected systems, transfer files, and run commands. Kaspersky noted the malware is made to ensure persistence on systems by utilizing BrockenDoor.

A separate group named Bearlyfy used ransomware—specifically LockBit 3.0 and Babuk—in a series of attacks on Russian firms, as reported by F6. Ransom amounts varied, with the highest reported demand near $86,000 in cryptocurrency. Bearlyfy reportedly relied on exploiting vulnerabilities in software like Bitrix and leveraged known privilege escalation flaws, which allow attackers to gain increased access to victims’ systems.

- Advertisement -

Investigation also revealed that Bearlyfy’s attack style differs from known groups. F6 explained, “Bearlyfy…uses a different model: attacks with minimal preparation and a targeted focus on achieving an immediate effect. The primary toolkit is aimed at encryption, destruction, or modification of data.” Although some infrastructure used aligns with the suspected pro-Ukrainian group PhantomCore, researchers believe Bearlyfy acts independently.

These attacks highlight ongoing cybersecurity risks faced by various organizations both within and connected to Russia.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

BRICS 2026: Modi pushes CBDC payment link at summit

The BRICS 2026 summit in New Delhi will spotlight a CBDC payment bridge to...

Base Accelerator Offers $100K to 10 AI Agent Startups

The Base accelerator plans to select 10 startups for its eight-week Batches 004 accelerator.Each...

Bitcoin Whales Accumulate Despite ETF Outflows

Bitcoin wallets holding at least 10,000 BTC climbed to 89, a six-month high, as...

GTA VI Leaks Used to Pump Crypto Token in ‘Secret Project’

A user called “CyberLeek” leaked GTA VI gameplay footage to promote a crypto token...

SEC’s new crypto rules mark shift from “inapt” to clear guidelines

SEC Commissioner Hester Peirce praised the agency's new crypto proposal as a shift from...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading