[ << ALL_FEED ]

CHM snap-in, alarm clocks, CIB of the Ministry of Defense of the Russian Federation, and bitcoin eggs

More in General

CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖

At the end of December last year, the Threat Intelligence team of the Positive Technologies Expert Security Center detected attacks that we attributed to the CapFix group, previously described by researchers.

The attackers used PDF documents that were disguised as “corrupted” and prompted users to download a RAR archive containing a script. This script downloaded a file named a.gif and renamed it to dmitry_medvedev.msi 😶, which subsequently led to the infection of the user with the CapDoor malware.

The group’s infrastructure masqueraded as legitimate domains associated with Windows updates and was registered via onionmail. But even more interesting is that the group used a number of legitimate IP addresses and domains, which, in our opinion, the attackers compromised approximately one month before the attacks themselves using CVE-2025-49113 👨‍💻

In March, the group resumed these attacks with a modified version of CapDoor, indicating that the attackers continue to develop their tool.

How exactly the attackers are developing CapDoor, how the group previously used ClickFix, and what bitcoin eggs have to do with it — read in our research ⬅️

#TI #APT #Malware
@ptescalator (X, Max)

More from ti_author

More from ti_author

More in General