Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
10 distinct techniques documented for this family, organized by ATT&CK tactic.
If the attacker enters only that prefix, it launches a SYSTEM command prompt on the secure desktop; if text follows the prefix, that text is executed as a command with the same level of access.
The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in.
Stupig registers itself as a keyboard-layout provider. Windows then loads it into the logon process at startup.
Backdoor.Stupig is a DLL backdoor that achieves persistence by registering as a keyboard-layout provider, causing win32k.sys to load it into winlogon.exe at system startup. This persistence mechanism is related to the Winlogon Helper DLL technique described in MITRE ATT&CK T1547.004 but uses a different registry loading path.
The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in.
Stupig registers itself as a keyboard-layout provider. Windows then loads it into the logon process at startup.
Backdoor.Stupig is a DLL backdoor that achieves persistence by registering as a keyboard-layout provider, causing win32k.sys to load it into winlogon.exe at system startup. This persistence mechanism is related to the Winlogon Helper DLL technique described in MITRE ATT&CK T1547.004 but uses a different registry loading path.
The second was Stupig, deployed first as a.dll and later renamed to closely mimic a legitimate Windows keyboard-layout library.
The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in.
Its design can give an attacker command execution as SYSTEM... while also creating an opportunity to intercept credentials entered during the sign-in process... Stupig also places hooks in Windows functions used during authentication and credential handling, allowing it to capture information inside winlogon.exe.
Its design can give an attacker command execution as SYSTEM... while also creating an opportunity to intercept credentials entered during the sign-in process... Stupig also places hooks in Windows functions used during authentication and credential handling, allowing it to capture information inside winlogon.exe.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy backdoor deployed as a DLL and disguised to resemble a legitimate Windows keyboard-layout library. It registers as a keyboard-layout provider so Windows loads it into the logon process at startup, then watches the logon screen for a specific username prefix and executes subsequent input as SYSTEM before sign-in while returning a normal failed-logon response.
A stealthy Windows backdoor that masquerades as a keyboard-layout provider so Windows loads its malicious DLL into winlogon.exe at startup. It watches the logon screen for usernames beginning with a special prefix, can spawn a SYSTEM command shell or execute commands before user logon, and hooks authentication and credential-handling functions to capture information inside winlogon.exe.
A previously undocumented DLL backdoor that persists by registering as a keyboard-layout provider so it is loaded into winlogon.exe at startup. It enables pre-authentication SYSTEM command execution from the Windows logon screen, hooks logon-related APIs for credential interception, and references a missing companion payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.