Katz Stealer DLL Loaded

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Detects DLL loads associated with 2025 Katz Stealer variants used to steal sensitive user and system information.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "Image Loaded" AND (OBJECTNAME endswith "\katz_ontop.dll" OR OBJECTNAME endswith "\AppData\Local\Temp\received_dll.dll") select Action1.HOSTNAME,Action1.MESSAGE,Action1.PROCESSNAME,Action1.PRODUCT_NAME,Action1.OBJECTNAME,Action1.SIGNATURE,Action1.SIGNATURESTATUS

Detection

Execution Mode

realtime

Log Sources

Windows

Author

@Swachchhanda Shrawan Poudel (Nextron Systems)