COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure — Threadlinqs Intelligence
As of 2026-07-19, COLDRIVER (UNC4057/Star Blizzard) Re-Tools with NOROBOT/BAITSWITCH/YESROBOT/MAYBEROBOT/SIMPLEFIX Malware Chain After LOSTKEYS Disclosure is a high-severity malware threat attributed to Cold River (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 54 indicators of compromise.
Threat ID: TL-2026-1510 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Cold River · Russia · ESPIONAGE
Russian state-sponsored group COLDRIVER (aka UNC4057, Star Blizzard, Callisto) rapidly re-tooled within five days of its May 2025 LOSTKEYS disclosure, deploying a new ClickFix-style infection chain
COLDRIVER (UNC4057/Star Blizzard/Callisto), a Russian FSB-linked state-sponsored intelligence-collection actor, operationalized an entirely new malware chain within five days of the public disclosure of its LOSTKEYS VBS stealer in May 2025. The new chain begins with a ClickFix social-engineering lure (internally COLDCOPY) presenting a fake Cloudflare Turnstile/CAPTCHA 'verify you are not a robot' page that instructs the victim to copy a command into the Windows Run dialog, executing `rundll32.exe` against a remotely-hosted DLL (`iamnotarobot.dll` / `checkme.dll` / `machinerie.dll`) exporting `humanCheck` or `verifyme`. This DLL downloader — tracked as NOROBOT by GTIG and independently as BAITSWITCH by Zscaler — establishes registry- and logon-script-based persistence, splits AES decryption keys across multiple registry values (`EnthusiastMode`, `QatItems`, and a custom `.pietas` class key) and multiple network fetches to frustrate single-artifact analysis, deletes `RunMRU` history to cover tracks, and retrieves a PowerShell stager that decrypts and loads a backdoor on next logon. Between May and early June 2025 the downloader delivered YESROBOT, a Python 3.8 backdoor requiring a bundled SFX Python interpreter install, HTTPS beaconing with base64-encoded system info in the User-Agent, AES-encrypted command retrieval, and execution restricted to raw Python code — assessed by GTIG as a hastily-built, noisy stopgap abandoned after only two observed victims. From June 2025 onward COLDRIVER shifted to MAYBEROBOT (SIMPLEFIX in Zscaler's naming), a heavily obfuscated PowerShell backdoor with a compact three-command custom HTTPS protocol (download-and-execute, cmd.exe command execution, PowerShell block execution) that avoids the Python dependency, beacons roughly every three minutes with hostname/username/machine-UUID identifiers, and remained functionally unchanged through the September 2025 observation window — indicating high operator confidence in its stability and evasion. The downloader itself continued to iterate: simplified in June 2025 to a single-fetch/single-persistence model, then deliberately re-complicated in late August 2025 with re-introduced key-splitting and multi-stage downloads, reflecting a deliberate operational-security trade-off between deployment speed and defender reconstruction difficulty. Targeting is consistent with COLDRIVER's long-running mission: NGOs, policy advisors, journalists, think tanks, former NATO/Western government and intelligence officials, and exiled members of Russian civil society (human rights defenders, educators, civic activists), often lured with decoy documents themed around resilience programs for exiled Russians. The chain is fully living-off-the-land and social-engineering driven — no CVE or software vulnerability is exploited; compromise depends entirely on the victim manually executing an attacker-supplied command. Google added all observed domains and hashes to Safe Browsing, issued government-backed-attacker warnings to targeted Gmail/Workspace users, and published YARA detection rules for NOROBOT, YESROBOT, and MAYBEROBOT. The rapid five-day re-tooling turnaround after the LOSTKEYS takedown, combined with a mature, unchanged backdoor and iterative downloader hardening over four months, indicates pre-built contingency tooling and sustained resourcing consistent with an FSB-directed persistent-access mission against Western and Russian-diaspora targets.
Weaknesses (CWE)
CWE-506, CWE-494
Target sectors: government administration, non-profit organisation, think-tank, civil society, diplomatic, defense, news - media
Target regions: North America, Europe, united kingdom, russia, Ukraine-adjacent
Related threats
- UAC-0099 Abuses Notepad++ Plugin Loading (CVE-2025-56383) to Deploy LunchPoke, BurnyBear, MatchBoil V2 Malware
- GTIG: Threat Actor Usage of AI Tools — 'Just-in-Time' AI-Enabled Malware (PROMPTFLUX, PROMPTSTEAL/LAMEHUG, PROMPTLOCK, FRUITSHELL, QUIETVAULT) Deployed by State Actors
- ACR Stealer (Amatera Stealer) Uses ClickFix Lures, WebDAV/pushd DLL Delivery, and EtherHiding to Harvest Browser and Microsoft 365 Data
- UAT-11795 (Russian) Trojanizes WebEx, Zoom, MobaXterm, DBeaver, FaceIT Installers to Deploy Starland RAT and Bespoke WLDR C2 Implant
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 54 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
Community OSINT corroboration
6 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1204, T1204.004, T1059.001, T1059.003, T1059.005, T1059.006, T1053.005, T1037.001, T1547.011