Kapeka
MITRE ATT&CK: S1190 View on attack.mitre.org
Aliases: KnuckleTouch, ICYWELL, KNUCKLETOUCH, QUEUESEED, WRONGSENS, Kapeka
- First seen
- 2022-06-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:08:02
Targeted industries: government-and-public-sector transportation-and-logistics energy-and-utilities
Targeted regions: country_code:ua country_code:ru
Context
Kapeka is a backdoor written in C++ used against victims in Eastern Europe since at least mid-2022. Kapeka has technical overlaps with Exaramel for Windows and Prestige malware variants, both of which are linked to Sandworm Team. Kapeka may have been used in advance of Prestige deployment in late 2022.
Detection coverage
- 2 YARA rules
- 284 Sigma rules
Malware & tools used
- Rundll32 (attack-pattern)
- Masquerade File Type (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Modify Registry (attack-pattern)
- Scheduled Task (attack-pattern)
- Web Protocols (attack-pattern)
- Clear Persistence (attack-pattern)
- Standard Encoding (attack-pattern)
- Query Registry (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Proxy (attack-pattern)
- Native API (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
Used by threat actors
- Sandworm Team (threat-actor)
Detection rules
- SEKOIA_Apt_Queueseed (yara-rule)
- MALPEDIA_Win_Kapeka_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Kapeka (report)
- CERT-UA — 6278706 (report)
- threatmon.io — Understanding The Kapeka Backdoor Detailed Analysis By Apt44 (report)
- labs.withsecure.com — Withsecure Research Kapeka (report)
- threatmon.io — Understanding The Kapeka Backdoor Detailed Analysis By Apt44 (report)
- ctfiot.com — 183017 (report)
- MITRE ATT&CK — S1190 (report)
- Microsoft — Malware Encyclopedia Description (report)