Malware.View on attack.mitre.org
SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection. SplatCloak has been deployed by SplatDropper and is known to be leveraged by Mustang Panda since 2025.
| Technique | Procedure example |
|---|---|
| T1036.001 Invalid Code Signature |
SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load. |
| T1082 System Information Discovery |
SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later). |
| T1083 File and Directory Discovery |
SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky. |
| T1106 Native API |
SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`. |
| T1518.001 Security Software Discovery |
SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates. |
| T1685 Disable or Modify Tools |
SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.