Russian APT Deploys New 'Kapeka' Backdoor in Eastern European Attacks
ID: ba348240-f612-5391-8d3f-69a4fc5c9414
STIX ID: report--ba348240-f612-5391-8d3f-69a4fc5c9414
Feed Name: The Hacker News
The report details Kapeka, a flexible Windows DLL backdoor observed since mid-2022 targeting Eastern Europe and attributed to the Russia-linked APT Sandworm; it uses a dropper that establishes persistence (scheduled task or autorun), communicates with actor-controlled C2 servers via WinHttp/JSON, supports file read/write, command execution, payload launches, on-the-fly C2 updates, and has been linked to ransomware campaigns (including probable ties to Prestige) while leveraging living-off-the-land tooling (certutil).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
