CapFix Uses Evolving CapDoor Malware in Attacks on Russian Organizations

Summary
Positive Technologies details CapFix campaigns targeting Russian industrial and aviation organizations with phishing lures, compromised infrastructure and evolving CapDoor malware capable of executing commands, downloading payloads and capturing screenshots.
Key points
- The researchers detected CapFix campaigns targeting Russian organizations, including industrial and aviation companies, from late 2025 through March 2026.
- Phishing PDFs and HTML files prompted victims to download malicious archives; the attacks used CHM scripts and MSI installers disguised as legitimate software.
- CapFix used compromised legitimate infrastructure for delivery and command-and-control. Researchers suspect access may have involved the critical Roundcube vulnerability CVE-2025-49113.
- Recent CapDoor versions use a multistage DLL sideloading chain to load shellcode, establish persistence through a Windows autorun registry key and communicate with C2 servers.
- CapDoor can run PowerShell commands, download and execute files, and capture screenshots; payloads observed alongside it included SectopRAT and ArechClient2.
- The report describes the malware’s evolution and links earlier campaigns to cryptocurrency and hotel-booking lures using ClickFix; the researchers say the AsyncRAT campaigns cannot be definitively attributed to CapFix.
Article Details
- Attack Vectors
- Phishing PDFs linked to RAR archives hosted on compromised legitimate sites. The archives contained scripts or installers that deployed CapDoor.
- Mass-mailed phishing emails targeted aviation companies, manufacturing companies, and an educational institution. Some lures impersonated Russian government structures.
- Malicious HTML files displayed apparently legitimate documents and prompted users to download additional files to unlock them.
- Earlier activity used cryptocurrency-themed files and hotel-booking phishing pages employing ClickFix. The researchers consider the attribution of the AsyncRAT-based ClickFix attacks to CapFix probable, not definitive.
- The researchers suspect the attackers gained access to compromised mail infrastructure through CVE-2025-49113 in Roundcube Webmail; they did not confirm the intrusion method.
- CapDoor was launched through a multistage DLL-sideloading chain involving a legitimate signed executable and encrypted payload files.
- Defensive Notes
- Positive Technologies lists PT Sandbox, PT AV, and PT EDR verdicts or behavioral rules for CapDoor-related files and behavior, including DLL side-loading and Windows autorun modification.
- The article lists network verdicts for CapDoor check-ins and SectopRAT.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | andreiushakov[.]ru | Domain tied by the researchers to the phishing-email actor; they observed no attacks originating from it. |
| DOMAIN | booking[.]fleps-extranet[.]com | Malicious ClickFix domain reached through an attacker-used GitHub Pages redirect. |
| DOMAIN | booking[.]l-extranet[.]com | Malicious hotel-booking-themed domain used in an AsyncRAT ClickFix campaign whose attribution to CapFix is not definitive. |
| DOMAIN | ddmmitriypetrovv[.]ru | Domain used to send the attackers' mass phishing emails. |
| DOMAIN | documents-sed[.]com | Additional domain the researchers linked to the threat actor through its registration. |
| DOMAIN | leonidkalatov[.]ru | Domain tied by the researchers to the phishing-email actor; they observed no attacks originating from it. |
| DOMAIN | microsoftpathes[.]com | Windows-update-themed domain tied to the email address used to register an attacker-controlled CapDoor C2 domain. |
| DOMAIN | securityswindows[.]com | Windows-update-themed domain tied to the email address used to register an attacker-controlled CapDoor C2 domain. |
| DOMAIN | sed-documents[.]com | Additional domain the researchers linked to the threat actor through its registration. |
| DOMAIN | support-archiver[.]com | Domain that delivered a RAR archive containing an MSI that ultimately installed CapDoor. |
| DOMAIN | windowsextupdates[.]com | Attacker-controlled domain used for CapDoor C2 communications and later for payload delivery. |
salasunion@onionmail[.]org | Email address used to register additional domains linked to the threat actor. | |
virrtasuin93@onionmail[.]org | Email address the attackers used to register Windows-update-themed domains, including a CapDoor C2 domain. | |
| IPV4 | 85[.]192[.]49[.]81 | C2 server contacted by CapDoor samples; the article also links it to earlier AsyncRAT ClickFix activity. |
| IPV4 | 94[.]156[.]232[.]113 | C2 server contacted by CapDoor samples. |
| SHA256 | 23f693029d8e00999a1c0e68d72884fd55f874582780afb94dbb1d3f8fb07f38 | SHA-256 of a malicious PDF that linked to an archive on a compromised site. |
| URL | hxxps[:]//windowsextupdates[.]com/updates/latest/q/Document[.]rar | Attacker-controlled URL used to download a malicious archive in the March 2026 attacks. |
MITRE ATT&CK
T1027 · Obfuscated Files or InformationAnalyzed components contained junk code using GDI functions, and encrypted payloads were stored in WAV or DAT files.T1055.012 · Process HollowingThe researchers report that earlier CapDoor versions used process hollowing to execute the backdoor.T1059.001 · PowerShellCapDoor supported C2 tasks that launched powershell.exe to execute arbitrary PowerShell commands.T1082 · System Information DiscoveryCapDoor collected operating-system version, build, architecture, server status, and other host details for its C2 message.T1105 · Ingress Tool TransferCapDoor could download executables, DLLs, or MSI files from its C2 server and run or install them.T1113 · Screen CaptureCapDoor could capture the main display and transmit PNG screenshot data to its C2 server.T1140 · Deobfuscate/Decode Files or InformationThe DLL chain decrypted an external payload before executing its shellcode; loader shellcode also decrypted the CapDoor payload.T1204.002 · Malicious FileThe infection chain depended on a recipient opening a downloaded archive and executing its script or installer.T1218.010 · Regsvr32One CapDoor download-task subtype silently registered a downloaded DLL through regsvr32.exe.T1218.011 · Rundll32One CapDoor download-task subtype executed a downloaded DLL through rundll32.exe.T1547.001 · Registry Run Keys / Startup FolderThe loader added the legitimate executable used in the infection chain to the current user's Windows Run registry key.T1566.001 · Spearphishing AttachmentThe attackers mass-mailed phishing PDFs and emails that prompted recipients to obtain CapDoor-delivering files.T1574.002 · DLL Side-LoadingCapDoor's installation chain launched a legitimate executable that sideloaded DLLs leading to the payload.
CVE
People
Threat Actors
Malware
ArechClient2In these samples, SectopRAT or ArechClient2 was used as the final payload.AsyncRATa month prior—in September and October 2025—the CapDoor C2 server at 85.192.49.81 was used for AsyncRAT in ClickFix campaigns. For example, in October, the attackers used the domain booking.l-extranet.comCapDoorThe criminals used a modified version of the CapDoor backdoor to download next-stage payloads, such as SectopRAT.GHOSTPULSEInstead of the DLL sideloading chain, attackers used the GHOSTPULSE loader (IDATLOADER or HIJACKLOADER) to load CapDoor.HIJACKLOADERInstead of the DLL sideloading chain, attackers used the GHOSTPULSE loader (IDATLOADER or HIJACKLOADER) to load CapDoor.IDATLOADERInstead of the DLL sideloading chain, attackers used the GHOSTPULSE loader (IDATLOADER or HIJACKLOADER) to load CapDoor.SectopRATThe criminals used a modified version of the CapDoor backdoor to download next-stage payloads, such as SectopRAT.
Products
PT AVPT AVPT EDRPT EDRPT SandboxPT Sandbox analysis fragment of Document.msiQILING Disk MasterThe .msi file was signed QILING Tech and masqueraded as the QILING Disk Master application. When run, it created the Disk Master folder in C:\Users\admin\AppData\Local\ and dropped numerous DLLs alongside a legitimateRoundcube WebmailIn late December and earlier, when the attackers were actively running campaigns, this host was vulnerable to CVE-2025-49113—a critical vulnerability (CVSS 9.9) in the popular Roundcube Webmail client.
Countries
Industries
AviationWe detected CapFix campaigns targeting Russian organizations in the industrial and aviation sectors.EducationIndustrialWe detected CapFix campaigns targeting Russian organizations in the industrial and aviation sectors.Manufacturingattacker had mass-mailed to various organizations. The targets included two aviation companies, four manufacturing companies, and one educational institution.