Unlock Exclusive Cybersecurity Learning Resources — Free & Limited-Time Offer!

ENROLL NOW

Enroll for CEH & Sec+ Hands-on Training Combo - get up to 30% Discount

A major escalation in the ongoing Russia-focused cyber threat landscape has unfolded as the COLDRIVER group, alongside BO Team and Bearlyfy, launches new multi-stage malware campaigns. From the Wiseman Cybersec perspective, this coordinated surge represents both a technical evolution in attacker capabilities and a critical shift in the cyberwarfare dynamics impacting Russian, Western, and civil society targets.

The COLDRIVER Campaign: Arsenal Expansion

In September 2025, Zscaler ThreatLabz documented COLDRIVER, a Russia-linked APT also known as Star Blizzard, Callisto, and UNC4057, ramping up its operations with two new lightweight malware strains: BAITSWITCH and SIMPLEFIX. COLDRIVER’s attack chain leverages ClickFix, a social engineering technique that lures targets—often NGOs, journalists, and human rights activists in both the West and Russia—into running malicious code disguised as legitimate actions, such as completing CAPTCHA checks.

BO Team and Bearlyfy: Counteroffensive and New Tactics

In parallel, threat groups BO Team (aka Black Owl, Hoody Hyena) and Bearlyfy are waging sophisticated attacks inside Russia. Their campaigns target both public and private sectors:

Bearlyfy’s infrastructure shows technical overlap with pro-Ukrainian threat groups, yet evidence points to it being an independent actor. Notably, Bearlyfy attacks often exploit vulnerabilities in external services (e.g., Bitrix, Zerologon), favouring immediate impact over drawn-out espionage.

Analysis: The Implications for Cybersecurity and Geopolitics

Wiseman Cybersec’s Recommendations

Conclusion

The emergence of COLDRIVER’s new malware alongside the disruptive activities of BO Team and Bearlyfy marks a pivotal evolution in Russia-focused cyber conflicts. Wiseman Cybersec urges organisations to move beyond conventional defence and engage layered, adaptive security measures—blending technical hardening with rapid threat intelligence collaboration—to defend against this fast-maturing, multi-front threat environment.

Leave a Reply

Your email address will not be published. Required fields are marked *

GET A FREE CONSULTATION

CISM Training by Wiseman Cybersec
wisemancybersec.com
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.