Threat Group – COLDRIVER
Threat Type – Espionage malware and social engineering
Exploited Vulnerabilities – User execution via ClickFix lure, abuse of rundll32, script execution and registry-based persistence (no CVEs assigned)
Malware Used – BAITSWITCH downloader, SIMPLEFIX PowerShell backdoor, LOSTKEYS VBS payload, SPICA backdoor
Threat Score – 8.2 🔴 High
Last Threat Observation – 25 September