InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs
Technology

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

October 18, 2025 3 Min Read
Share
New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs
SHARE

Cybersecurity researchers have identified a previously undocumented .NET malware. CAPI backdoor.

According to Seqrite Labs, the attack chain includes distributing phishing emails with ZIP archives as a method of causing infection. The cybersecurity firm’s analysis is based on a ZIP artifact uploaded to the VirusTotal platform on October 3, 2025.

The archive contains decoy Russian language documents and Windows shortcut (LNK) files disguised as notifications related to the Income Tax Act.

The LNK file with the same name as the ZIP archive (i.e. “Перерасчет заработной платы 01.10.2025”) runs a .NET implant (“adobe.dll”) using the genuine Microsoft binary (LotL) technique called “rundll32.exe”. Known to be employed by threat actors.

According to Seqrite, the backdoor has the ability to check if it is running with administrator-level privileges, collect a list of installed antivirus products, and open a decoy document as a ruse, while secretly connecting to a remote server (91.223.75(.)96) to receive further commands for execution.

This command allows CAPI backdoors to steal data from web browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox. Take a screenshot. Collect system information. Enumerate the contents of a folder. It then extracts the results and sends them back to the server.

It also tries to perform a long list of checks to determine whether it is a legitimate host or a virtual machine. It also uses two methods to establish persistence. This includes configuring scheduled tasks and creating an LNK file in the Windows Startup folder to automatically launch backdoor DLLs that are copied to the Windows Roaming folder.

Seqrite’s assessment that this actor is targeting the Russian automotive sector is due to the fact that one of the domains linked to the campaign is named carprlce(.)ru, which appears to be masquerading as the legitimate “carprice(.)ru”.

See also  Batshadow Group hunts job seekers using the new GO-based "Vampire Bot" malware

“The malicious payload is a .NET DLL that acts as a stealer and establishes persistence against future malicious activity,” researchers Priya Patel and Subhajeet Singha said.

Share This Article
Twitter Copy Link
Previous Article A new demo for medieval RPG Norse, which combines the combat of BG3 with the charm of Kingdom Come Deliverance 2, has been added to your Steam wishlist A new demo for medieval RPG Norse, which combines the combat of BG3 with the charm of Kingdom Come Deliverance 2, has been added to your Steam wishlist
Next Article 'No Kings' protests against Trump bring street party atmosphere to cities across the US ‘No Kings’ protests against Trump bring street party atmosphere to cities across the US

Latest News

Researchers discover more than 30 flaws in AI coding tools that enable data theft and RCE attacks

Researchers discover more than 30 flaws in AI coding tools that enable data theft and RCE attacks

More than 30 security vulnerabilities have been uncovered in various…

December 6, 2025
Zero-click agent browser attack could delete entire Google Drive using crafted email

Zero-click agent browser attack could delete entire Google Drive using crafted email

New agent browser attack targeting Perplexity's Comet browser. A seemingly…

December 5, 2025
Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

Silver Fox uses fake Microsoft Teams installer to spread ValleyRAT malware in China

threat actor known as silver fox In attacks targeting Chinese…

December 4, 2025
Critical RSC bug in React and Next.js allows unauthenticated remote code execution

Critical RSC bug in React and Next.js allows unauthenticated remote code execution

A maximum severity security flaw has been disclosed in React…

December 3, 2025
India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India orders messaging apps to work only with active SIM cards to prevent fraud and abuse

India's Department of Telecommunications (DoT) has directed app-based telecom service…

December 2, 2025

You Might Also Like

comicform and sectorJ149 hacker deploys form book malware in Eurasian cyberattack
Technology

comicform and sectorJ149 hacker deploys form book malware in Eurasian cyberattack

5 Min Read
WhatsApp malware 'Maverick' hijacks browser sessions and targets Brazil's largest banks
Technology

WhatsApp malware ‘Maverick’ hijacks browser sessions and targets Brazil’s largest banks

9 Min Read
UNC1549 Hacking 34 devices from 11 telecom companies via LinkedIn Job Lures and Minibike malware
Technology

UNC1549 Hacking 34 devices from 11 telecom companies via LinkedIn Job Lures and Minibike malware

8 Min Read
The FBI warns UNC6040 and UNC6395 targeting Salesforce platforms in data theft attacks
Technology

The FBI warns UNC6040 and UNC6395 targeting Salesforce platforms in data theft attacks

5 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?