⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Malware

Stupig Pre-Logon Backdoor: Novel Keyboard-Layout DLL Attack

July 16, 2026

Stupig (a.dll or kbdus1.dll) is a DLL backdoor that achieves persistence by registering as a keyboard-layout provider, causing win32k.sys to load it into winlogon.exe at system startup. It monitors for usernames beginning with 'stupig' and executes commands with SYSTEM privileges from the Windows logon screen before user sign-in, without raising logon audit events.