Kapeka Backdoor Loaded Via Rundll32.EXE — Detection Rule

Detects the Kapeka Backdoor binary being loaded by rundll32.exe. The Kapeka loader drops a backdoor, which is a DLL with the '.wll' extension masquerading as a Microsoft Word Add-In.

Read the full analysis on IntelFusions