Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

President Trump to headline America’s 250th anniversary celebration after artist declines

This 5-year piano learning app offer has been reduced to just $68, making it cheaper than ever.

Taylor Swift completed ‘Toy Story 5’ song in ‘hectic’ 8 hours

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs
Celebrities

New .NET CAPI backdoor targets Russian car and e-commerce companies via phishing ZIPs

By October 18, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

October 18, 2025Ravi LakshmananThreat Intelligence/Cybercrime

Cybersecurity researchers have uncovered a new campaign likely targeting Russia’s automotive and e-commerce industries using a previously undocumented .NET malware called “CAPI Backdoor.”

According to Seqrite Labs, the attack chain includes distributing phishing emails with ZIP archives as a method of causing infection. The cybersecurity firm’s analysis is based on a ZIP artifact uploaded to the VirusTotal platform on October 3, 2025.

The archive contains decoy Russian language documents and Windows shortcut (LNK) files disguised as notifications related to the Income Tax Act.

The LNK file with the same name as the ZIP archive (i.e. “Перерасчет заработной платы 01.10.2025”) runs a .NET implant (“adobe.dll”) using the genuine Microsoft binary (LotL) technique called “rundll32.exe”. Known to be employed by threat actors.

DFIR retainer service

According to Seqrite, the backdoor has the ability to check if it is running with administrator-level privileges, collect a list of installed antivirus products, and open a decoy document as a ruse, while secretly connecting to a remote server (‘91.223.75’).[.]96″) to receive further commands.

This command allows CAPI backdoors to steal data from web browsers such as Google Chrome, Microsoft Edge, and Mozilla Firefox. Take a screenshot. Collect system information. Enumerate the contents of a folder. It then extracts the results and sends them back to the server.

It also tries to perform a long list of checks to determine whether it is a legitimate host or a virtual machine. It also uses two methods to establish persistence. This includes configuring scheduled tasks and creating an LNK file in the Windows Startup folder to automatically launch backdoor DLLs that are copied to the Windows Roaming folder.

Seqrite’s assessment that this actor is targeting the Russian automotive sector is based on the fact that one of the domains associated with the campaign is named carprlce.[.]ru, it seems to be masquerading as the official “carprice”[.]Ru. ”

“The malicious payload is a .NET DLL that acts as a stealer and establishes persistence against future malicious activity,” researchers Priya Patel and Subhajeet Singha said.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous Article3,500-year-old Egyptian military fortress with ancient oven and fossilized fabric discovered in Sinai desert
Next Article Methane ‘switch’ discovered in Arctic Ocean that promotes rapid global warming

Related Posts

Rama Dowaj Styles Upcycled Knicks Shirt by Claire Sullivan

June 18, 2026

New York Knicks’ most stylish players

June 18, 2026

The meaning behind Michelle Obama’s vintage photo skirt

June 17, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

President Trump to headline America’s 250th anniversary celebration after artist declines

This 5-year piano learning app offer has been reduced to just $68, making it cheaper than ever.

Taylor Swift completed ‘Toy Story 5’ song in ‘hectic’ 8 hours

Hot rivalry crushes competition in 13 categories at Canadian Screen Awards

Trending Posts

Taylor Swift completed ‘Toy Story 5’ song in ‘hectic’ 8 hours

June 18, 2026

John Waters talks Mosswood meltdown, AI lighting, the Pope and more

June 18, 2026

Sakurazaka46 “Lonely Usagi” ranks first on the JAPAN HOT 100

June 18, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.