Kapeka

MITRE ATT&CK: S1190 View on attack.mitre.org

Aliases: KnuckleTouch, ICYWELL, KNUCKLETOUCH, QUEUESEED, WRONGSENS, Kapeka

First seen
2022-06-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:08:02

Targeted industries: government-and-public-sector transportation-and-logistics energy-and-utilities

Targeted regions: country_code:ua country_code:ru

Context

Kapeka is a backdoor written in C++ used against victims in Eastern Europe since at least mid-2022. Kapeka has technical overlaps with Exaramel for Windows and Prestige malware variants, both of which are linked to Sandworm Team. Kapeka may have been used in advance of Prestige deployment in late 2022.

Detection coverage

  • 2 YARA rules
  • 284 Sigma rules

Malware & tools used

  • Rundll32 (attack-pattern)
  • Masquerade File Type (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Modify Registry (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Web Protocols (attack-pattern)
  • Clear Persistence (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Query Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Proxy (attack-pattern)
  • Native API (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)

Used by threat actors

Detection rules

  • SEKOIA_Apt_Queueseed (yara-rule)
  • MALPEDIA_Win_Kapeka_Auto (yara-rule)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Win.Kapeka (report)
  • CERT-UA — 6278706 (report)
  • threatmon.io — Understanding The Kapeka Backdoor Detailed Analysis By Apt44 (report)
  • labs.withsecure.com — Withsecure Research Kapeka (report)
  • threatmon.io — Understanding The Kapeka Backdoor Detailed Analysis By Apt44 (report)
  • ctfiot.com — 183017 (report)
  • MITRE ATT&CK — S1190 (report)
  • Microsoft — Malware Encyclopedia Description (report)

External references