logo

Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor

ID: 7f40c0a5-0177-55bd-95dc-4d0b75bcc21b

STIX ID: report--7f40c0a5-0177-55bd-95dc-4d0b75bcc21b

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-07-11

Date Updated: 2026-07-21

Author: Eswar

...
...

Doctor Web documents a sophisticated multi-stage Windows Trojan first seen in late 2025 that compromises developer machines by infecting Visual Studio project files (.vcxproj, .csproj, .suo) and build components to distribute a backdoor/infostealer, clipboard hijacker, cryptominer, and file infector; it uses advanced TTPs (PEB walking, initterm abuse, DLL replacement, named pipes, UAC bypass), leverages public services and social platforms as covert C2 channels, and can exfiltrate credentials and crypto assets while persisting through supply-chain contamination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.