CHM snap-in, alarm clocks, CIB of the Ministry of Defense of the Russian Federation, and bitcoin eggs

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
CHM snap-in, alarms, CIB of the Russian Ministry of Defense, and bitcoin eggs 🤖
At the end of December last year, the Threat Intelligence team of the Positive Technologies Expert Security Center detected attacks that we attributed to the CapFix group, previously described by researchers.
The attackers used PDF documents that were disguised as “corrupted” and prompted users to download a RAR archive containing a script. This script downloaded a file named a.gif and renamed it to dmitry_medvedev.msi 😶, which subsequently led to the infection of the user with the CapDoor malware.
The group’s infrastructure masqueraded as legitimate domains associated with Windows updates and was registered via onionmail. But even more interesting is that the group used a number of legitimate IP addresses and domains, which, in our opinion, the attackers compromised approximately one month before the attacks themselves using CVE-2025-49113 👨💻
In March, the group resumed these attacks with a modified version of CapDoor, indicating that the attackers continue to develop their tool.
How exactly the attackers are developing CapDoor, how the group previously used ClickFix, and what bitcoin eggs have to do with it — read in our research ⬅️
#TI #APT #Malware
@ptescalator (X, Max)
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



