Kapeka Backdoor Execution Via RunDLL32.EXE — Detection Rule

Detects Kapeka backdoor process execution pattern, where the dropper launch the backdoor binary by calling rundll32 and passing the backdoor's first export ordinal (#1) with a "-d" argument.

Read the full analysis on IntelFusions