SIMPLEFIX is a PowerShell-based backdoor associated with the Russia-linked threat actor COLDRIVER, also tracked as Star Blizzard, Callisto, and UNC4057. It has been reported as part of a ClickFix-style intrusion chain targeting civil society connected to Russia, including NGOs, human rights defenders, think tanks in Western regions, and individuals exiled from and residing in Russia. In this chain, victims are lured via fake CAPTCHA pages into executing a malicious DLL through the Windows Run dialog; the BAITSWITCH downloader then retrieves and deploys SIMPLEFIX. Zscaler independently reported the BAITSWITCH/SIMPLEFIX chain, while Google identified the same backdoor as MAYBEROBOT.
SIMPLEFIX communicates with command-and-control infrastructure to execute PowerShell scripts, shell commands, and binaries hosted at remote URLs. Reported capabilities include downloading and executing payloads, executing commands through the Windows command prompt, executing arbitrary PowerShell blocks, and returning execution results to distinct C2 paths for operator feedback. A PowerShell script run via SIMPLEFIX exfiltrates information about a hard-coded list of file types from a pre-configured list of directories; the targeted directories and file extensions overlap with those used by COLDRIVER’s earlier LOSTKEYS malware. The broader operation using BAITSWITCH and SIMPLEFIX was described as enabling persistence, reconnaissance, and data exfiltration.
Known infrastructure directly mentioned in reporting includes BAITSWITCH contacting captchanom[.]top to fetch the backdoor and a PowerShell stager contacting southprovesolutions[.]com to download SIMPLEFIX. High-confidence aliases and naming overlap in the provided content indicate that SIMPLEFIX is the same malware Google reported as MAYBEROBOT.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
"...another backdoor, a PowerShell script called MAYBEROBOT..." and "execute arbitrary PowerShell blocks"
"...supports three commands: ... execute commands through the command prompt"
"...uses a hardcoded C2 and a custom protocol... In all cases an acknowledgement is sent to the C2 at a different path... output is sent to a third path."
"download and execute payloads from a specified URL" and "initially retrieved a full Python 3.8 installation for Windows"
2 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Lightweight malware family delivered by BAITSWITCH in ClickFix-style attacks; no further details in excerpt.
A named COLDRIVER-associated delivery/social-engineering chain reported by Zscaler, referenced alongside BAITSWITCH. No further technical detail is provided in the content.
Zscaler’s name for the backdoor payload associated with the Robot toolchain; described as a PowerShell backdoor (aligned with MAYBEROBOT) used for command execution and payload retrieval.
PowerShell backdoor delivered by BAITSWITCH; establishes C2 communications to execute PowerShell scripts/commands and retrieve additional binaries from remote URLs, including scripts that exfiltrate files matching specified extensions from specified directories.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.