216.73.217.98

Sophisticated backdoor mimicking secure networking software updates

· Published 22/04/2025 18:02 · Modified 22/04/2025 22:50

Export JSON

Essential information

Published
22/04/2025 18:02
Modified
22/04/2025 22:50
Tags
2025-04-22 apt backdoor c2 server heur:trojan.win32.loader.gen path substitution payload russia secure networking software updates targeted attack vipnet
Related entities
6 techniques (mitre), 1 malware, 3 others

Description

A sophisticated targeting Russian organizations in government, finance, and industry sectors was discovered masquerading as updates for software. The malware, distributed in LZH archives, exploits a technique to execute a malicious loader that deploys a versatile . This can connect to a , steal files, and launch additional malicious components. The attack highlights the increasing complexity of group tactics and emphasizes the need for multi-layered security defenses to protect against such sophisticated threats.

External references