logo

Russian APT Deploys New 'Kapeka' Backdoor in Eastern European Attacks

ID: ba348240-f612-5391-8d3f-69a4fc5c9414

STIX ID: report--ba348240-f612-5391-8d3f-69a4fc5c9414

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2024-04-17

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

The report details Kapeka, a flexible Windows DLL backdoor observed since mid-2022 targeting Eastern Europe and attributed to the Russia-linked APT Sandworm; it uses a dropper that establishes persistence (scheduled task or autorun), communicates with actor-controlled C2 servers via WinHttp/JSON, supports file read/write, command execution, payload launches, on-the-fly C2 updates, and has been linked to ransomware campaigns (including probable ties to Prestige) while leveraging living-off-the-land tooling (certutil).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.