Kapeka, also tracked by Microsoft as KnuckleTouch, is a Windows backdoor associated with the Russian state-linked Sandworm threat cluster, also known as APT44 or Seashell Blizzard. It has been observed in operations targeting Eastern Europe, including Ukraine and Estonia, since at least mid-2022, and is assessed to support both early-stage intrusion activity and long-term access on compromised systems. Reporting has also linked it to ransomware distribution activity and to intrusions that preceded Prestige ransomware deployment, with technical overlaps suggesting it may be a successor to GreyEnergy in Sandworm’s toolset.
Kapeka is implemented as a Windows DLL written in C++ and is executed through rundll32.exe, including ordinal-based execution. It has been disguised as a Microsoft Word add-in to reduce suspicion. The malware contains embedded command-and-control configuration data, communicates with command-and-control infrastructure using JSON-formatted messages, and uses multithreading to receive tasks, process them, and return results. It can collect host information, read and write files, execute shell commands and additional payloads, update its own configuration from the server, upgrade itself, and uninstall itself.
Persistence is established through an accompanying dropper that launches the backdoor and then deletes itself. Persistence mechanisms include scheduled tasks and, in some cases, autorun registry entries depending on privilege level. Kapeka also stores and retrieves configuration data in the Windows Registry and can identify system proxy settings for subsequent command-and-control operations. Public reporting indicates the exact initial infection vector remains unknown, although retrieval of the dropper from compromised websites via native Windows tooling has been documented in some cases.
Kapeka is best characterized as a flexible access-enablement and post-compromise backdoor used in espionage and disruptive operations. Its combination of stealthy DLL-based execution, durable persistence, remote command execution, payload delivery, and configuration management makes it suitable for sustained operations against government and regional targets in Eastern Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
据芬兰网络安全公司WithSecure称,一种名为Kapeka的以前未记录的“灵活”后门已经在至少从2022年中期以来针对东欧,包括爱沙尼亚和乌克兰的网络攻击中“零星”出现。微软将同一恶意软件跟踪名称命名为KnuckleTouch。
26 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
During the 2022 Ukraine Electric Power Attack, Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution. | Many malware families store configuration, payloads, encryption keys, C2 addresses, or other operational data in Registry keys, such as QakBot storing configuration in a randomly named subkey under HKCU\Software\Microsoft and PolyglotDuke writing encrypted JSON configuration files to the Registry.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
Kapeka masquerades as a Microsoft Word Add-In file, with the extension .wll, but is a malicious DLL file.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes threat actors and malware modifying, creating, deleting, or storing data in Windows Registry keys and values for persistence, configuration storage, defense evasion, credential access, privilege escalation, and execution. | Many malware families store configuration, payloads, encryption keys, C2 addresses, or other operational data in Registry keys, such as QakBot storing configuration in a randomly named subkey under HKCU\Software\Microsoft and PolyglotDuke writing encrypted JSON configuration files to the Registry.
Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server... Kapeka utilizes JSON objects to send and receive information from command and control nodes... Mori can use Base64 encoded JSON libraries used in C2... Remcos can serialize collected data with Protobuf.
Kapeka utilizes JSON objects to send and receive information from command and control nodes. Emotet has used Google’s Protobufs to serialize data sent to and from the C2 server. Remcos can serialize collected data with Protobuf.
后门使用WinHttp 5.1 COM接口(winhttpcom.dll)来实现其网络通信组件。后门与其C2通信以轮询任务并将指纹信息和任务结果发送回来。后门利用JSON从其C2发送和接收信息。
The content repeatedly describes threat actors, malware, and campaigns using HTTP and/or HTTPS for command and control, including examples such as BlackEnergy communicating with C2 over HTTP POST requests and many other families using HTTP/S for C2.
AuditCred can utilize proxy for communications... FunnyDream can identify and use configured proxies in a compromised network for C2 communication... Kapeka can identify system proxy settings via WinHttpGetIEProxyConfigForCurrentUser() during initialization and utilize these settings for subsequent command and control operations... PoshC2 contains modules that allow for use of proxies in command and control.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Novel backdoor observed in Eastern Europe and independently attributed to Seashell Blizzard/APT44 by multiple vendors.
Kapeka is a flexible Windows DLL backdoor written in C++ that establishes persistence, communicates with embedded C2 infrastructure over WinHTTP using JSON, fingerprints infected hosts, receives and executes commands, reads/writes files, launches payloads, executes shell commands, updates its C2 configuration, and can upgrade or uninstall itself. A dropper launches the backdoor and removes itself, with persistence set via scheduled tasks or autorun registry keys. The malware is described as enabling long-term access and has been linked to credential theft, data theft, destructive activity, remote access, and ransomware delivery.
Backdoor malware used for initial exploitation and persistent access, linked to Russian Sandworm group, and possibly associated with ransomware operations.
Malicious DLL disguised as a Microsoft Word Add-In (.wll) file.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.