By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
Computing

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

News Room
Last updated: 2025/10/18 at 7:51 AM
News Room Published 18 October 2025
Share
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
SHARE

Oct 18, 2025Ravie LakshmananThreat Intelligence / Cybercrime

Cybersecurity researchers have shed light on a new campaign that has likely targeted the Russian automobile and e-commerce sectors with a previously undocumented .NET malware dubbed CAPI Backdoor.

According to Seqrite Labs, the attack chain involves distributing phishing emails containing a ZIP archive as a way to trigger the infection. The cybersecurity company’s analysis is based on the ZIP artifact that was uploaded to the VirusTotal platform on October 3, 2025.

Present with the archive is a decoy Russian-language document that purports to be a notification related to income tax legislation and a Windows shortcut (LNK) file.

The LNK file, which has the same name as the ZIP archive (i.e., “Перерасчет заработной платы 01.10.2025”), is responsible for the execution of the .NET implant (“adobe.dll”) using a legitimate Microsoft binary named “rundll32.exe,” a living-off-the-land (LotL) technique known to be adopted by threat actors.

DFIR Retainer Services

The backdoor, Seqrite noted, comes with functions to check if it’s running with administrator-level privileges, gather a list of installed antivirus products, and open the decoy document as a ruse, while it stealthily connects to a remote server (“91.223.75[.]96”) to receive further commands for execution.

The commands allow CAPI Backdoor to steal data from web browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox; take screenshots; collect system information; enumerate folder contents; and exfiltrate the results back to the server.

It also attempts to run a long list of checks to determine if it’s a legitimate host or a virtual machine, and makes use of two methods to establish persistence, including setting up a scheduled task and creating a LNK file in the Windows Startup folder to automatically launch the backdoor DLL copied to the Windows Roaming folder.

Seqrite’s assessment that the threat actor is targeting the Russian automobile sector is down to the fact that one of the domains linked to the campaign is named carprlce[.]ru, which appears to impersonate the legitimate “carprice[.]ru.”

“The malicious payload is a .NET DLL that functions as a stealer and establishes persistence for future malicious activities,” researchers Priya Patel and Subhajeet Singha said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Hackers Dox ICE, DHS, DOJ, and FBI Officials Hackers Dox ICE, DHS, DOJ, and FBI Officials
Next Article Digitize DVDs on the Quick With 50% Savings on This Ripper Tool Digitize DVDs on the Quick With 50% Savings on This Ripper Tool
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Gurman: Apple launching iOS 26.2 beta ‘as soon as Tuesday,’ following iOS 26.1 debut – 9to5Mac
Gurman: Apple launching iOS 26.2 beta ‘as soon as Tuesday,’ following iOS 26.1 debut – 9to5Mac
News
The Best Audiophile Headphones We’ve Reviewed for 2025
The Best Audiophile Headphones We’ve Reviewed for 2025
News
NASM 3.00 Assembler Is Ready With Intel APX & AVX10 Support
NASM 3.00 Assembler Is Ready With Intel APX & AVX10 Support
Computing
The 5 Most Common HDMI Input Problems (And How To Fix Them) – BGR
The 5 Most Common HDMI Input Problems (And How To Fix Them) – BGR
News

You Might also Like

NASM 3.00 Assembler Is Ready With Intel APX & AVX10 Support
Computing

NASM 3.00 Assembler Is Ready With Intel APX & AVX10 Support

1 Min Read
The TechBeat: Can ChatGPT Outperform the Market? Week 11 (11/2/2025) | HackerNoon
Computing

The TechBeat: Can ChatGPT Outperform the Market? Week 11 (11/2/2025) | HackerNoon

7 Min Read
Linux 6.18-rc4 Introducing More AMD 6 Model IDs, Other x86 Fixes
Computing

Linux 6.18-rc4 Introducing More AMD 6 Model IDs, Other x86 Fixes

2 Min Read
Perforator 0.0.7 Released With New Features For Continuous Performance Profiling
Computing

Perforator 0.0.7 Released With New Features For Continuous Performance Profiling

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?