Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe

Flags rundll32.exe loading a suspicious .wll backdoor from ProgramData or AppData\Local.

FreeReviewedSigma · High · v5
Product
windows
Category
image_load
Author
Swachchhanda Shrawan Poudel (SigmaHQ), DRL 1.1
Published
2024-07-03
Updated
2026-07-31

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies rundll32.exe loading a DLL with a .wll extension from user or program data locations. The behavior aligns with a loader that deploys a backdoor DLL masquerading as a legitimate Word add-in to evade attention. It relies on image load telemetry that provides the process image name and the loaded module path.

Related detections9 linkedT1204.002 — drag to rearrange
Malicious rundll32 Execution of COLDCOPY DLL via COLDRIVER ClickFix
Suspicious n8n Campaign RMM Installer Masquerading as OneDrive Document
Suspicious NFe-Themed Brazilian Lure Executable Execution
Malicious Zardoor Backdoor Execution via rundll32 (via process_creation)
Suspicious Executable Dropped in Public Users Directory Named Ctrlpanel (via file_event)
Suspicious Interlock Fake Updater Executable Execution
Malicious Office Application Loading a User-Path DLL via Regsvr32 or Rundll32 (via process_creation)
Suspicious Program Execution From a Mounted ISO or Disk Image (via process_creation)
Malicious Rundll32 Loading an Export From a User Path (via process_creation)
Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe
Pivot detection · T1204.002 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.