Malware.View on attack.mitre.org
SplatDropper is a loader that utilizes native windows API to deliver its payload to the victim environment. SplatDropper has been delivered through RAR archives and used legitimate executable for DLL side-loading. SplatDropper is known to be leveraged by Mustang Panda and was first observed utilized in 2025.
| Technique | Procedure example |
|---|---|
| T1027.007 Dynamic API Resolution |
SplatDropper has leveraged hashed Windows API calls using a seed value of "131313". |
| T1027.013 Encrypted/Encoded File |
SplatDropper has also utilized XOR encrypted payload. |
| T1070.009 Clear Persistence |
SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices. |
| T1106 Native API |
SplatDropper has utilized hashed Native Windows API calls. |
| T1140 Deobfuscate/Decode Files or Information |
SplatDropper has decoded XOR encrypted payload. |
| T1543.003 Windows Service |
SplatDropper has created a service to execute a payload. |
| T1553.002 Code Signing |
SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1574.001 DLL |
SplatDropper has leveraged legitimate binaries to conduct DLL side-loading. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.