Kapeka, also known as KnuckleTouch, originally appeared in mid-2022 but was formally tracked in 2024 due to limited-scope attacks, particularly in Eastern Europe. The Kapeka backdoor is linked to the Sandstorm Group, which is run by Russia’s Military Unit 74455 and is notorious for disrupting cyber activity.
Source: LogPoint