PULSE NAME
IOC - Operation MotorBeacon : Threat Actor targets Russian Automotive Sector using .NET Implant
WHITE celestre 2025-10-22 Modified: 2025-11-21
11
IOCs
MEDIUM VOLUME
SEQRITE Labs Research Team has recently uncovered a campaign which involves targeting Russian Automobile-Commerce industry which involves commercial as well as automobile oriented transactions , we saw the use of unknown .NET malware which we have dubbed as CAPI Backdoor. In this blog, we will explore the technical details of this campaign we encountered during our initial analysis and examine the various stages of the infection chain, starting with a deep dive into the decoy document, to analyzing the CAPI Backdoor. we will then look into the infrastructure along with the common tactics , techniques and procedures (TTPs).
Indicators of Compromise (3 / 11 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 957b34952d92510e95df02e3600b8b21 2025-10-22
FileHash-MD5 c0adfd84dfae8880ff6fd30748150d32 2025-10-22
FileHash-MD5 c6a6fcec59e1eaf1ea3f4d046ee72ffe 2025-10-22