Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

Posted on October 18, 2025October 18, 2025 By CWS

Oct 18, 2025Ravie LakshmananThreat Intelligence / Cybercrime
Cybersecurity researchers have make clear a brand new marketing campaign that has doubtless focused the Russian car and e-commerce sectors with a beforehand undocumented .NET malware dubbed CAPI Backdoor.
In accordance with Seqrite Labs, the assault chain includes distributing phishing emails containing a ZIP archive as a approach to set off the an infection. The cybersecurity firm’s evaluation is predicated on the ZIP artifact that was uploaded to the VirusTotal platform on October 3, 2025.
Current with the archive is a decoy Russian-language doc that purports to be a notification associated to earnings tax laws and a Home windows shortcut (LNK) file.
The LNK file, which has the identical title because the ZIP archive (i.e., “Перерасчет заработной платы 01.10.2025”), is accountable for the execution of the .NET implant (“adobe.dll”) utilizing a official Microsoft binary named “rundll32.exe,” a living-off-the-land (LotL) approach recognized to be adopted by risk actors.

The backdoor, Seqrite famous, comes with capabilities to examine if it is working with administrator-level privileges, collect an inventory of put in antivirus merchandise, and open the decoy doc as a ruse, whereas it stealthily connects to a distant server (“91.223.75[.]96”) to obtain additional instructions for execution.
The instructions enable CAPI Backdoor to steal information from internet browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox; take screenshots; accumulate system info; enumerate folder contents; and exfiltrate the outcomes again to the server.

It additionally makes an attempt to run a protracted record of checks to find out if it is a official host or a digital machine, and makes use of two strategies to determine persistence, together with organising a scheduled activity and making a LNK file within the Home windows Startup folder to robotically launch the backdoor DLL copied to the Home windows Roaming folder.
Seqrite’s evaluation that the risk actor is focusing on the Russian car sector is right down to the truth that one of many domains linked to the marketing campaign is known as carprlce[.]ru, which seems to impersonate the official “carprice[.]ru.”
“The malicious payload is a .NET DLL that capabilities as a stealer and establishes persistence for future malicious actions,” researchers Priya Patel and Subhajeet Singha mentioned.

The Hacker News Tags:.NET, Auto, Backdoor, CAPI, ECommerce, Firms, Phishing, Russian, Targets, ZIPs

Post navigation

Previous Post: PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution
Next Post: New Phishing Attack Leverages Azure Blob Storage to Impersonate Microsoft

Related Posts

SolarWinds Releases Hotfix for Critical CVE-2025-26399 Remote Code Execution Flaw The Hacker News
CTM360 Identifies Surge in Phishing Attacks Targeting Meta Business Users The Hacker News
New Linux Flaws Allow Password Hash Theft via Core Dumps in Ubuntu, RHEL, Fedora The Hacker News
Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks The Hacker News
RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware The Hacker News
DOJ Charges 22-Year-Old for Running RapperBot Botnet Behind 370,000 DDoS Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Personal Information Compromised in Freedom Mobile Data Breach
  • 5 Threats That Reshaped Web Security This Year [2025]
  • Marquis Data Breach Impacts Over 780,000 People
  • Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens
  • New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Personal Information Compromised in Freedom Mobile Data Breach
  • 5 Threats That Reshaped Web Security This Year [2025]
  • Marquis Data Breach Impacts Over 780,000 People
  • Hackers Using Evilginx to Steal Session Cookies and Bypass Multi-Factor Authentication Tokens
  • New ‘Sryxen’ Stealer Bypasses Chrome Encryption via Headless Browser Technique

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark