Most Significant TTP 2026: RC4-Encrypted Second-Stage Payload Decryption Precedi

Detects behavior indicative of the MLTBackdoor malware, specifically the creation or modification of a DLL file (such as *dlp.dll) shortly after or before the creation of an RC4-encrypted 'data.bin' file on the same host. The rule also looks for an optional preceding archive extraction event of common file types from Temp or Downloads directories by standard extraction utilities, which may indicate the staging of the initial payload.