ATT&CKSoftwareSplatCloak

SplatCloak

S1234

Malware.View on attack.mitre.org

About this malware

SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection. SplatCloak has been deployed by SplatDropper and is known to be leveraged by Mustang Panda since 2025.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1036.001
Invalid Code Signature

SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load.

T1082
System Information Discovery

SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later).

T1083
File and Directory Discovery

SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky.

T1106
Native API

SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`.

T1518.001
Security Software Discovery

SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates.

T1685
Disable or Modify Tools

SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.