Kapeka

S1190

Malware.View on attack.mitre.org

About this malware

Kapeka is a backdoor written in C++ used against victims in Eastern Europe since at least mid-2022. Kapeka has technical overlaps with Exaramel for Windows and Prestige malware variants, both of which are linked to Sandworm Team. Kapeka may have been used in advance of Prestige deployment in late 2022.

Techniques used14

Procedure examples14

TechniqueProcedure example
T1012
Query Registry

Kapeka queries registry values for stored configuration information.

T1027.013
Encrypted/Encoded File

Kapeka utilizes AES-256 (CBC mode), XOR, and RSA-2048 encryption schemas for various configuration and other objects.

T1036.008
Masquerade File Type

Kapeka masquerades as a Microsoft Word Add-In file, with the extension `.wll`, but is a malicious DLL file.

T1053.005
Scheduled Task

Kapeka persists via scheduled tasks.

T1059.003
Windows Command Shell

Kapeka allows for arbitrary Windows command execution.

T1070.009
Clear Persistence

Kapeka will clear registry values used for persistent configuration storage when uninstalled.

T1071.001
Web Protocols

Kapeka utilizes HTTP for command and control.

T1082
System Information Discovery

Kapeka utilizes WinAPI calls and registry queries to gather system information.

T1090
Proxy

Kapeka can identify system proxy settings via `WinHttpGetIEProxyConfigForCurrentUser()` during initialization and utilize these settings for subsequent command and control operations.

T1106
Native API

Kapeka utilizes WinAPI calls to gather victim system information.

T1112
Modify Registry

Kapeka writes persistent configuration information to the victim host registry.

T1132.001
Standard Encoding

Kapeka utilizes JSON objects to send and receive information from command and control nodes.

T1140
Deobfuscate/Decode Files or Information

Kapeka utilizes obfuscated JSON structures for various data storage and configuration management items.

T1218.011
Rundll32

Kapeka is a Windows DLL file executed via ordinal by `rundll32.exe`.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Microsoft KnuckleTouch 2024 Open source
    Microsoft. (2024, February 14). Backdoor:Win64/KnuckleTouch.A!dha. Retrieved January 6, 2025.
  2. WithSecure Kapeka 2024 Open source
    Mohammad Kazem Hassan Nejad, WithSecure. (2024, April 17). KAPEKA A novel backdoor spotted in Eastern Europe. Retrieved January 6, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.