By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
Computing

New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

News Room
Last updated: 2025/10/18 at 7:51 AM
News Room Published 18 October 2025
Share
New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
SHARE

Oct 18, 2025Ravie LakshmananThreat Intelligence / Cybercrime

Cybersecurity researchers have shed light on a new campaign that has likely targeted the Russian automobile and e-commerce sectors with a previously undocumented .NET malware dubbed CAPI Backdoor.

According to Seqrite Labs, the attack chain involves distributing phishing emails containing a ZIP archive as a way to trigger the infection. The cybersecurity company’s analysis is based on the ZIP artifact that was uploaded to the VirusTotal platform on October 3, 2025.

Present with the archive is a decoy Russian-language document that purports to be a notification related to income tax legislation and a Windows shortcut (LNK) file.

The LNK file, which has the same name as the ZIP archive (i.e., “Перерасчет заработной платы 01.10.2025”), is responsible for the execution of the .NET implant (“adobe.dll”) using a legitimate Microsoft binary named “rundll32.exe,” a living-off-the-land (LotL) technique known to be adopted by threat actors.

DFIR Retainer Services

The backdoor, Seqrite noted, comes with functions to check if it’s running with administrator-level privileges, gather a list of installed antivirus products, and open the decoy document as a ruse, while it stealthily connects to a remote server (“91.223.75[.]96”) to receive further commands for execution.

The commands allow CAPI Backdoor to steal data from web browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox; take screenshots; collect system information; enumerate folder contents; and exfiltrate the results back to the server.

It also attempts to run a long list of checks to determine if it’s a legitimate host or a virtual machine, and makes use of two methods to establish persistence, including setting up a scheduled task and creating a LNK file in the Windows Startup folder to automatically launch the backdoor DLL copied to the Windows Roaming folder.

Seqrite’s assessment that the threat actor is targeting the Russian automobile sector is down to the fact that one of the domains linked to the campaign is named carprlce[.]ru, which appears to impersonate the legitimate “carprice[.]ru.”

“The malicious payload is a .NET DLL that functions as a stealer and establishes persistence for future malicious activities,” researchers Priya Patel and Subhajeet Singha said.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Hackers Dox ICE, DHS, DOJ, and FBI Officials Hackers Dox ICE, DHS, DOJ, and FBI Officials
Next Article Digitize DVDs on the Quick With 50% Savings on This Ripper Tool Digitize DVDs on the Quick With 50% Savings on This Ripper Tool
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

8 best noise-cancelling headphones for flying, tested to improve your travel experience
8 best noise-cancelling headphones for flying, tested to improve your travel experience
News
E.ON taps Nokia for comms network modernisation | Computer Weekly
E.ON taps Nokia for comms network modernisation | Computer Weekly
News
Shein Might Be Cheap, But Is It Legit? – BGR
Shein Might Be Cheap, But Is It Legit? – BGR
News
I love uBlock, but it’s not the first browser extension I install on my phone
I love uBlock, but it’s not the first browser extension I install on my phone
News

You Might also Like

How to Bulk Schedule Pinterest Pins Using Tailwind and Ideogram
Computing

How to Bulk Schedule Pinterest Pins Using Tailwind and Ideogram

5 Min Read
Debian’s APT Will Soon Begin Requiring Rust: Debian Ports Need To Adapt Or Be Sunset
Computing

Debian’s APT Will Soon Begin Requiring Rust: Debian Ports Need To Adapt Or Be Sunset

2 Min Read
How I Use ChatGPT to Create Affiliate Blogs
Computing

How I Use ChatGPT to Create Affiliate Blogs

7 Min Read
ChatGPT as a soccer advisor: Seattle Reign FC coach uses AI to develop new defensive strategy — and it worked
Computing

ChatGPT as a soccer advisor: Seattle Reign FC coach uses AI to develop new defensive strategy — and it worked

2 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?