ATT&CKReferencesZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025

Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software3

Campaigns0

None recorded.

Procedure examples39

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwarePAKLOG

PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows.

T1027
Obfuscated Files or Information
GroupMustang Panda

Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis.

T1027.007
Dynamic API Resolution
MalwareSplatDropper

SplatDropper has leveraged hashed Windows API calls using a seed value of "131313".

T1027.013
Encrypted/Encoded File
MalwarePAKLOG

PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer.

T1027.013
Encrypted/Encoded File
MalwareSplatDropper

SplatDropper has also utilized XOR encrypted payload.

T1027.013
Encrypted/Encoded File
MalwareCorKLOG

CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings.

T1036.001
Invalid Code Signature
MalwareSplatCloak

SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load.

T1053.005
Scheduled Task
MalwareCorKLOG

CorKLOG has achieved persistence through the creation of a scheduled task named TableInputServices by using the command `schtasks /create /tn TabletlnputServices /tr /sc minute /mo 10 /f`.

T1056.001
Keylogging
MalwareCorKLOG

CorKLOG has captured keystrokes.

T1056.001
Keylogging
MalwarePAKLOG

PAKLOG has captured keystrokes using Windows API.

T1057
Process Discovery
MalwarePAKLOG

PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls.

T1070.004
File Deletion
GroupMustang Panda

Mustang Panda will delete their tools and files, and kill processes after their objectives are reached.

T1070.009
Clear Persistence
MalwareSplatDropper

SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices.

T1074.001
Local Data Staging
MalwarePAKLOG

PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`.

T1074.001
Local Data Staging
MalwareCorKLOG

CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key.

T1082
System Information Discovery
MalwareSplatCloak

SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later).

T1083
File and Directory Discovery
MalwareSplatCloak

SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky.

T1106
Native API
MalwareSplatDropper

SplatDropper has utilized hashed Native Windows API calls.

T1106
Native API
MalwarePAKLOG

PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions.

T1106
Native API
GroupMustang Panda

Mustang Panda has used various Windows API calls during execution and defense evasion.

T1106
Native API
MalwareSplatCloak

SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`.

T1115
Clipboard Data
MalwarePAKLOG

PAKLOG has monitored and extracted clipboard contents.

T1124
System Time Discovery
MalwarePAKLOG

PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S.

T1140
Deobfuscate/Decode Files or Information
MalwareSplatDropper

SplatDropper has decoded XOR encrypted payload.

T1140
Deobfuscate/Decode Files or Information
MalwareCorKLOG

CorKLOG has decoded XOR encrypted strings.

T1204.002
Malicious File
GroupMustang Panda

Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim.

T1518.001
Security Software Discovery
MalwareSplatCloak

SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates.

T1543.003
Windows Service
MalwareCorKLOG

CorKLOG has created a service to establish persistence.

T1543.003
Windows Service
MalwareSplatDropper

SplatDropper has created a service to execute a payload.

T1553.002
Code Signing
MalwareCorKLOG

CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1553.002
Code Signing
MalwareSplatDropper

SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1553.002
Code Signing
MalwarePAKLOG

PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading.

T1553.002
Code Signing
GroupMustang Panda

Mustang Panda has used valid legitimate digital signatures and certificates to evade detection.

T1574.001
DLL
GroupMustang Panda

Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs.

T1574.001
DLL
MalwareCorKLOG

CorKLOG has leveraged legitimate binaries to conduct DLL side-loading.

T1574.001
DLL
MalwarePAKLOG

PAKLOG has leveraged legitimate binaries to conduct DLL side-loading.

T1574.001
DLL
MalwareSplatDropper

SplatDropper has leveraged legitimate binaries to conduct DLL side-loading.

T1588.003
Code Signing Certificates
GroupMustang Panda

Mustang Panda has used revoked code signing certificates for its malicious payloads.

T1685
Disable or Modify Tools
MalwareSplatCloak

SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.