News Room
16
Share
COLDRIVER Hackers Deploy New Malware Families via ClickFix Social Engineering Lures
highThreat Intelligence

COLDRIVER Hackers Deploy New Malware Families via ClickFix Social Engineering Lures

Russian-linked threat actor COLDRIVER has launched a new espionage campaign using sophisticated ClickFix-style lures. The attacks leverage fake CAPTCHA prompts to execute malicious PowerShell scripts.

25 August 2026Last updated 25 August 20264 min readOffSeq Threat Radar
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Threat Intelligence
Severity:
High
Actor Type:
Nation-State
Geography:
Europe
Confidence:
High Confidence
Source:
OffSeq Threat Radar
Read Time:
4 min

Executive Summary

Recent intelligence indicates that the Russian-aligned threat actor group known as COLDRIVER has pivoted its operational focus. While historically recognized for credential theft targeting high-profile individuals, the group has now deployed three previously undocumented malware families. These campaigns utilize social engineering tactics disguised as security verification processes to compromise target systems.

Threat Analysis

The campaign utilizes a technique known as 'ClickFix,' where users are presented with a deceptive browser-based interface mimicking a CAPTCHA verification. When the user interacts with the prompt, they are instructed to copy and run a command in the Windows Run dialog. This command is a base64-encoded PowerShell script that initiates the infection chain, allowing the threat actor to gain a foothold on the victim's machine.

Technical Details

The newly identified malware families exhibit advanced evasion capabilities, including cryptographic key splitting and modular delivery mechanisms. The infection chain relies on legitimate Windows utilities, specifically 'rundll32.exe' and 'PowerShell,' to execute malicious payloads. By masquerading as standard system maintenance or security verification, the malware successfully bypasses traditional signature-based detection. The payloads are designed for persistent intelligence gathering, with the ability to exfiltrate sensitive data and maintain long-term access to the compromised environment.

Attribution Assessment

Security researchers have attributed this activity to COLDRIVER, a group with a history of state-sponsored espionage. The recent arrest of suspects in the Netherlands linked to COLDRIVER operations suggests that while the group faces increased international scrutiny, its operational capacity remains high. The shift toward broader intelligence gathering indicates a strategic evolution in their mission profile.

Implications

This campaign highlights the persistent danger of social engineering, even when users are trained to recognize traditional phishing. By weaponizing the 'Run' dialog and mimicking common security workflows, COLDRIVER has effectively lowered the barrier for successful exploitation. Organizations must prepare for an increase in 'living-off-the-land' attacks that abuse native system tools to evade security software.

Recommendations

  1. Implement strict endpoint controls to restrict the execution of PowerShell scripts by non-administrative users. 2. Deploy advanced behavioral monitoring to detect anomalous use of 'rundll32.exe' and 'PowerShell' initiated from browser-based prompts. 3. Conduct targeted security awareness training focusing on the dangers of copying and executing commands from untrusted web sources. 4. Utilize EDR solutions to monitor for suspicious process lineage and unauthorized network connections originating from user-space applications.
Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo