Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
Stupig employs a novel technique, allowing attackers to execute commands with System privileges directly from the Windows logon screen before any user signs in, bypassing standard audit logs.
Whatever follows that prefix is treated as a command and executed with SYSTEM privileges... If someone types the prefix with nothing after it, the backdoor opens a command prompt with SYSTEM privileges directly on the login screen, before any user has authenticated.
The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in.
Defense Evasion Masquerading T1036 Stupig poses as kbdus1.dll mimicking the legitimate kbdus.dll and returns a valid keyboard-table pointer so the keyboard works normally.
Stupig employs a novel technique, allowing attackers to execute commands with System privileges directly from the Windows logon screen before any user signs in, bypassing standard audit logs.
The backdoor watches the logon screen for a specific username prefix. Anything typed after that prefix runs as SYSTEM, before anyone signs in.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used to execute commands with SYSTEM privileges and steal credentials in Taiwanese high-tech manufacturing environments.
Backdoor that hides as a keyboard-layout DLL loaded into winlogon.exe at startup. It enables pre-authentication SYSTEM command execution from the Windows logon screen without generating a logon audit event.
A DLL backdoor that masquerades as a keyboard-layout DLL to gain persistence and load into winlogon.exe at startup. It enables pre-authentication command execution with SYSTEM privileges from the Windows logon screen and supports credential theft while avoiding normal logon audit visibility.
A backdoor disguised as a legitimate Microsoft DLL that allows attackers to execute commands with System privileges directly from the Windows logon screen before user sign-in, bypassing standard audit logs.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.