A previously undocumented .NET-based malware, dubbed CAPI Backdoor, has been identified as the payload in a targeted phishing campaign against Russian automotive and e-commerce companies. The attack begins with spear-phishing emails containing a ZIP archive, which was first observed on VirusTotal on October 3, 2025. This ZIP file includes a Russian-language decoy document, purporting to be a notification about income tax legislation or payroll recalculation, and a malicious Windows shortcut (LNK) file. The LNK file, named identically to the ZIP archive, is engineered to execute the CAPI Backdoor DLL (adobe.dll) using the legitimate Windows binary rundll32.exe, a classic living-off-the-land (LotL) technique that helps evade detection. Once executed, the backdoor checks for administrator privileges, enumerates installed antivirus products, and opens the decoy document to distract the user while it operates covertly. The malware establishes persistence by creating a scheduled task and placing a shortcut in the Windows Startup folder, ensuring it runs on system reboot. CAPI Backdoor connects to a remote command-and-control server at 91.223.75[.]96, from which it can receive further instructions. Its capabilities include stealing data from popular web browsers such as Chrome, Edge, and Firefox, taking screenshots, collecting detailed system information, and enumerating folder contents for exfiltration. The malware also performs extensive checks to determine if it is running in a virtual machine or sandbox environment, likely as an anti-analysis measure. Infrastructure analysis revealed that one of the domains used in the campaign is linked to the Russian automotive sector, supporting the assessment that this industry is a primary target. The campaign also impacts the broader e-commerce sector within Russia, as indicated by the targeting patterns and decoy content. Seqrite Labs, which conducted the technical analysis, has provided indicators of compromise (IOCs) and mapped the attack to relevant MITRE ATT&CK techniques. The campaign demonstrates a sophisticated use of social engineering, leveraging localized decoy documents and legitimate system binaries to maximize infection success and persistence. The use of a previously unknown .NET implant highlights the evolving tactics of threat actors targeting Russian commercial sectors. Organizations in the affected industries are advised to update their security controls, educate employees about phishing risks, and monitor for the provided IOCs. The discovery underscores the ongoing threat posed by targeted phishing campaigns leveraging custom malware and advanced evasion techniques.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
SEQRITE Labs published research detailing the MotorBeacon operation, describing the .NET-based CAPI backdoor, associated stealer activity, and the campaign's focus on Russian automotive and e-commerce targets.
A threat campaign dubbed Operation MotorBeacon targeted organizations in Russia's automotive and e-commerce sectors using phishing-delivered ZIP archives that led to deployment of a .NET malware implant known as the CAPI backdoor and a .NET stealer.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceseqrite.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.