PAKLOG

S1233

Malware.View on attack.mitre.org

About this malware

PAKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. PAKLOG is deployed via a RAR archive (e.g., key.rar), which contains two files: a signed, legitimate binary (PACLOUD.exe) and the malicious PAKLOG DLL (pa_lang2.dll). The PACLOUD.exe binary is used to side-load the PAKLOG DLL which starts with the keylogger functionality.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1010
Application Window Discovery

PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows.

T1027.013
Encrypted/Encoded File

PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer.

T1056.001
Keylogging

PAKLOG has captured keystrokes using Windows API.

T1057
Process Discovery

PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls.

T1074.001
Local Data Staging

PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`.

T1106
Native API

PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions.

T1115
Clipboard Data

PAKLOG has monitored and extracted clipboard contents.

T1124
System Time Discovery

PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S.

T1553.002
Code Signing

PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading.

T1574.001
DLL

PAKLOG has leveraged legitimate binaries to conduct DLL side-loading.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.