Hackers Infect C++ and C# Project Files to Spread Multi-Stage Windows Backdoor
ID: 7f40c0a5-0177-55bd-95dc-4d0b75bcc21b
STIX ID: report--7f40c0a5-0177-55bd-95dc-4d0b75bcc21b
Feed Name: GBHackers
Doctor Web documents a sophisticated multi-stage Windows Trojan first seen in late 2025 that compromises developer machines by infecting Visual Studio project files (.vcxproj, .csproj, .suo) and build components to distribute a backdoor/infostealer, clipboard hijacker, cryptominer, and file infector; it uses advanced TTPs (PEB walking, initterm abuse, DLL replacement, named pipes, UAC bypass), leverages public services and social platforms as covert C2 channels, and can exfiltrate credentials and crypto assets while persisting through supply-chain contamination.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
