Close Menu
TechurzTechurz
    What's Hot

    India’s Yulu raises $93M as quick-commerce boom fuels e-bike demand

    August 12, 2026

    Phoebe Gates and Sophia Kianni reportedly knew Phia was ‘cookie stuffing’ for months

    August 11, 2026

    General Catalyst leads $1.1B round into 2-month-old River AI

    August 11, 2026
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Tech Pulse
    • India’s Yulu raises $93M as quick-commerce boom fuels e-bike demand
    • Phoebe Gates and Sophia Kianni reportedly knew Phia was ‘cookie stuffing’ for months
    • General Catalyst leads $1.1B round into 2-month-old River AI
    • Kyoto Fusioneering starts work on key fusion power plant device
    • Tech industry is buzzing after a Claude agent hacked into a gym
    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    TechurzTechurz
    • Home
    • Tech Pulse
    • Future Tech
    • AI Systems
    • Cyber Reality
    • Disruption Lab
    • Signals
    TechurzTechurz
    Home - Cyber Reality - New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
    Cyber Reality

    New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs

    TechurzBy TechurzOctober 18, 2025Updated:May 10, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    New .NET CAPI Backdoor Targets Russian Auto and E-Commerce Firms via Phishing ZIPs
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Oct 18, 2025Ravie LakshmananThreat Intelligence / Cybercrime

    Cybersecurity researchers have shed light on a new campaign that has likely targeted the Russian automobile and e-commerce sectors with a previously undocumented .NET malware dubbed CAPI Backdoor.

    According to Seqrite Labs, the attack chain involves distributing phishing emails containing a ZIP archive as a way to trigger the infection. The cybersecurity company’s analysis is based on the ZIP artifact that was uploaded to the VirusTotal platform on October 3, 2025.

    Present with the archive is a decoy Russian-language document that purports to be a notification related to income tax legislation and a Windows shortcut (LNK) file.

    The LNK file, which has the same name as the ZIP archive (i.e., “Перерасчет заработной платы 01.10.2025”), is responsible for the execution of the .NET implant (“adobe.dll”) using a legitimate Microsoft binary named “rundll32.exe,” a living-off-the-land (LotL) technique known to be adopted by threat actors.

    The backdoor, Seqrite noted, comes with functions to check if it’s running with administrator-level privileges, gather a list of installed antivirus products, and open the decoy document as a ruse, while it stealthily connects to a remote server (“91.223.75[.]96”) to receive further commands for execution.

    The commands allow CAPI Backdoor to steal data from web browsers like Google Chrome, Microsoft Edge, and Mozilla Firefox; take screenshots; collect system information; enumerate folder contents; and exfiltrate the results back to the server.

    It also attempts to run a long list of checks to determine if it’s a legitimate host or a virtual machine, and makes use of two methods to establish persistence, including setting up a scheduled task and creating a LNK file in the Windows Startup folder to automatically launch the backdoor DLL copied to the Windows Roaming folder.

    Seqrite’s assessment that the threat actor is targeting the Russian automobile sector is down to the fact that one of the domains linked to the campaign is named carprlce[.]ru, which appears to impersonate the legitimate “carprice[.]ru.”

    “The malicious payload is a .NET DLL that functions as a stealer and establishes persistence for future malicious activities,” researchers Priya Patel and Subhajeet Singha said.

    Auto backdoor CAPI ECommerce firms Net phishing Russian targets ZIPs
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleCISOs face quantum leap in prioritizing quantum resilience
    Next Article I’ve yet to find a pair of Bluetooth earbuds that nails comfort, audio, and price like this one
    Techurz
    • Website

    Related Posts

    Opinion

    AegisAI, founded by former Google security execs, lands $36M to stop AI-driven spear phishing

    July 23, 2026
    Opinion

    Cascade raises $3.5M to help construction firms find and win projects

    July 22, 2026
    Cyber Reality

    Digital Identity Protection: 7 Hidden Risks Most Users Miss

    May 25, 2026
    Add A Comment
    Latest Tech Pulse

    College social app Fizz expands into grocery delivery

    September 3, 20252,290

    12 Father’s Day E-Card Sites That Are Actually Good

    June 4, 202523

    SolarSquare in talks to raise up to $60M as India’s rooftop solar market draws major VC interest

    May 23, 202622
    Stay In Touch
    • YouTube
    • WhatsApp
    • Twitter
    • Pinterest
    • LinkedIn

    Techurz helps readers stay ahead of digital change with clear, practical, future focused technology intelligence written today,searched tomorrow.

    X (Twitter) Pinterest YouTube LinkedIn WhatsApp
    Company
    • About Us
    • Contact Us
    • Our Authors / Editorial Team
    • Write For Us
    • Advertise
    Policy
    • Editorial Policy
    • Privacy Policy
    • Terms and Conditions
    • Affiliate Disclosure
    • Cookie Policy
    • Disclaimer
    • DMCA
    Explore
    • AI Systems
    • Cyber Reality
    • Future Tech
    • Disruption Lab
    • Signals
    • Tech Pulse
    • Sitemap

    Join the Techurz Brief

    The future does not arrive suddenly.
    Stay ahead with fast, sharp tech signals.

    Type above and press Enter to search. Press Esc to cancel.