In recent weeks, security researchers have noticed an increase in targeted attacks attributed to the COLDRIVER APT group , which include the deployment of a new backdoor named BAITSWITCH.

It is a PowerShell-based backdoor that demonstrates advanced command and control techniques while embedding itself in legitimate Windows processes. It was first spotted in late July 2025, when infiltration attempts against government non-profit organizations in Southeast Asia began to increase, leveraging spear-phishing emails containing infected Office documents. These documents, when opened, silently executed PowerShell scripts that paved the way for BAITSWITCH. Early indicators suggest that the group improved its traps social engineering to mimic internal memos, increasing click-through rates among high-value targets.
See also: Malicious Rust Crates steal Solana and Ethereum keys
After these initial exploits, Zscaler noticed that BAITSWITCH deviates from typical script-based loaders by embedding its entire payload within coded PowerShell commands. Instead of downloading binaries directly from public repositories, the loader decompresses an encrypted module directly into memory. This approach minimizes the disk footprint, preventing detection by traditional antivirus tools.

Within a week of its appearance, Zscaler analysts detected attempts by BAITSWITCH operators. Specifically, they observed the use of built-in Windows utilities such as Invoke-Command and Get-Service to move around the network. By September 2025, incident response teams reported compromised Active Directory accounts in several organizations, with private documents and system snapshots being extracted.
BAITSWITCH's impact extends beyond data theft; its hidden communication channels have allowed the attacker to remain inactive for weeks before executing destructive payloads. Organizations with poor PowerShell logging or no network egress monitoring have proven particularly vulnerable.
See also: Android banking trojans mimic government apps
BAITSWITCH backdoor: Infection chain
The BAITSWITCH infection chain is based on a multi-stage PowerShell deployment sequence. First, victims receive a bait document with macros that execute a code snippet that decodes a Base64-encoded string containing the next-stage loader. The loader then executes an AES decryption using a hard-coded key within the script to reveal the final backdoor module.
Once decrypted, BAITSWITCH registers itself as a scheduled task named “WindowsUpdateSvc” and injects its commands into the svchost.exe process to evade detection. The backdoor communicates with its C2 server over HTTPS, disguising the traffic as regular Windows update requests. This infection mechanism highlights the COLDRIVER team’s emphasis on script-only payloads and operational security, complicating both detection and remediation efforts.
See also: BRICKSTORM: Chinese hackers had access to American companies for a year

Backdoor protection
Organizations can protect their networks from backdoors by implementing various security. First, it is important to keep their systems up to date. This means they should regularly install the latest updates and security patches on all operating systems and applications.
Additionally, organizations should use security solutions that include intrusion detection and malware protection. These solutions can help detect and prevent attacks.
Staff training is also critical to avoiding backdoors. Employees need to be aware of the risks associated with cybersecurity and the tactics used by attackers, such as phishing .
Finally, the principle of least access should be applied . This means that users and devices should only have the necessary access permissions they need to perform their tasks.
