Russian organizations targeted by backdoor masquerading as secure networking software updates
ID: b6b496e8-b214-50b8-ad3f-d35f611b73d9
STIX ID: report--b6b496e8-b214-50b8-ad3f-d35f611b73d9
Feed Name: Securelist by Kaspersky
Date Published: 2025-04-22
Date Updated: 2026-04-29
Author: Igor Kuznetsov, Georgy Kucherin, Alexander Demidov
Kaspersky investigated a sophisticated backdoor delivered in April 2025 by malicious LZH archives masquerading as ViPNet updates targeting government, finance, and industrial organizations in Russia; the archive used a legitimate updater (lumpdiag.exe) and path-substitution to run a malicious loader (msinfo32.exe) which decrypts and loads a backdoor capable of C2 communication and file theft, with associated hashes and file paths provided as IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
