BAITSWITCH is a Windows downloader attributed to the Russian state-sponsored threat actor COLDRIVER, also known as Star Blizzard, Callisto, and UNC4057. It has been used in ClickFix-style social-engineering campaigns against Russian dissidents, civil-society organizations, human-rights defenders, NGOs, think tanks, and Ukraine-related targets. Victims are induced by fake CAPTCHA or similar verification lures to execute a malicious DLL through the Windows Run dialog. BAITSWITCH profiles the compromised host, communicates with attacker infrastructure, retrieves follow-on payloads, and has been observed delivering the SIMPLEFIX PowerShell backdoor. It can receive instructions associated with persistence, store encrypted payloads in the Windows Registry, download a PowerShell stager, and remove the most recent Run-dialog command to reduce evidence of the initial execution. Related Star Blizzard delivery chains have also used password-protected archives and virtual-disk containers containing malicious shortcuts masquerading as documents, alongside scheduled-task persistence. BAITSWITCH has additionally been referenced in reporting as part of the CosmicPulse/NOROBOT malware-delivery chain.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Le downloader CosmicPulse (aussi connu sous NOROBOT ou BAITSWITCH) est compilé en DLL de panneau de contrôle (CPL) et exécuté via control.exe.
9 distinct techniques documented for this family, organized by ATT&CK tactic.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader designation for the CosmicPulse downloader component, which obtains further ZIP-packaged components during the RedFlick infection flow.
Downloader used in the RedFlick infection chain to deliver the CosmicPulse backdoor.
Downloader used in ClickFix-style attack chain to ultimately drop SIMPLEFIX.
A named COLDRIVER-associated delivery/social-engineering chain reported by Zscaler, mentioned as part of the actor’s evolving arsenal. The content does not describe payload behavior or technical implementation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.