Windows DLL Load Indicators for Katz Stealer 2025 Variants

Alerts on Windows image loads of DLLs with Katz Stealer-associated names/paths.

FreeReviewedSigma · High · v5
Product
windows
Category
image_load
Author
Swachchhanda Shrawan Poudel (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2025-05-22
Updated
2026-07-31

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows processes that load specific DLLs associated with Katz Stealer malware 2025 variants. Loading these DLL paths strongly indicates malicious behavior because the DLL names and locations are consistent with staged malware components. The detection relies on image-load telemetry that records the DLL path when it is loaded by a process.

Related detections2 linkedT1129 — drag to rearrange
Malicious Discord RAT Module Download from GitHub via Proxy
Windows ImageLoad of Unsigned .node Native Add-on Files
Windows DLL Load Indicators for Katz Stealer 2025 Variants
Pivot detection · T1129 · 2 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.