← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
IOC - Operation MotorBeacon : Threat Actor targets Russian Automotive Sector using .NET Implant
SEQRITE Labs Research Team has recently uncovered a campaign which involves targeting Russian Automobile-Commerce industry which involves commercial as well as automobile oriented transactions , we saw the use of unknown .NET malware which we have dubbed as CAPI Backdoor.
In this blog, we will explore the technical details of this campaign we encountered during our initial analysis and examine the various stages of the infection chain, starting with a deep dive into the decoy document, to analyzing the CAPI Backdoor. we will then look into the infrastructure along with the common tactics , techniques and procedures (TTPs).
Indicators of Compromise (3 / 11 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 957b34952d92510e95df02e3600b8b21 | — | 2025-10-22 | |
| FileHash-MD5 | c0adfd84dfae8880ff6fd30748150d32 | — | 2025-10-22 | |
| FileHash-MD5 | c6a6fcec59e1eaf1ea3f4d046ee72ffe | — | 2025-10-22 |