logo

Russian organizations targeted by backdoor masquerading as secure networking software updates

ID: b6b496e8-b214-50b8-ad3f-d35f611b73d9

STIX ID: report--b6b496e8-b214-50b8-ad3f-d35f611b73d9

Feed Name: Securelist by Kaspersky

Threat Score
78/100

Date Published: 2025-04-22

Date Updated: 2026-04-29

Author: Igor Kuznetsov, Georgy Kucherin, Alexander Demidov

...
...

Kaspersky investigated a sophisticated backdoor delivered in April 2025 by malicious LZH archives masquerading as ViPNet updates targeting government, finance, and industrial organizations in Russia; the archive used a legitimate updater (lumpdiag.exe) and path-substitution to run a malicious loader (msinfo32.exe) which decrypts and loads a backdoor capable of C2 communication and file theft, with associated hashes and file paths provided as IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.