Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1010 Application Window Discovery |
MalwarePAKLOG | PAKLOG has used `GetForegroundWindow` to access the foreground window. PAKLOG has also captured text from the foreground windows. |
| T1027 Obfuscated Files or Information |
GroupMustang Panda | Mustang Panda has delivered initial payloads hidden using archives and encoding measures. Mustang Panda has also utilized opaque predicates in payloads to hinder analysis. 2022 November_TrendMicro_Earth Preta_Toneshell_PubloadAnomali MUSTANG PANDA October 2019Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018Eset PlugX Korplug Mustang Panda March 2022Proofpoint TA416 Europe March 2022Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Secureworks BRONZE PRESIDENT December 2019Sophos PlugX September 2022Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1027.007 Dynamic API Resolution |
MalwareSplatDropper | SplatDropper has leveraged hashed Windows API calls using a seed value of "131313". |
| T1027.013 Encrypted/Encoded File |
MalwarePAKLOG | PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer. |
| T1027.013 Encrypted/Encoded File |
MalwareSplatDropper | SplatDropper has also utilized XOR encrypted payload. |
| T1027.013 Encrypted/Encoded File |
MalwareCorKLOG | CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings. |
| T1036.001 Invalid Code Signature |
MalwareSplatCloak | SplatCloak has used a revoked certificate to exploit Windows driver execution policy where certificates issued before a specific date could still load. |
| T1053.005 Scheduled Task |
MalwareCorKLOG | CorKLOG has achieved persistence through the creation of a scheduled task named TableInputServices by using the command `schtasks /create /tn TabletlnputServices /tr /sc minute /mo 10 /f`. |
| T1056.001 Keylogging |
MalwareCorKLOG | CorKLOG has captured keystrokes. |
| T1056.001 Keylogging |
MalwarePAKLOG | PAKLOG has captured keystrokes using Windows API. |
| T1057 Process Discovery |
MalwarePAKLOG | PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls. |
| T1070.004 File Deletion |
GroupMustang Panda | Mustang Panda will delete their tools and files, and kill processes after their objectives are reached. |
| T1070.009 Clear Persistence |
MalwareSplatDropper | SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices. |
| T1074.001 Local Data Staging |
MalwarePAKLOG | PAKLOG has stored the captured data in a file located `C:\\Users\\Public\\Libraries\\record.txt`. |
| T1074.001 Local Data Staging |
MalwareCorKLOG | CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key. |
| T1082 System Information Discovery |
MalwareSplatCloak | SplatCloak has collected the Windows build number using the windows kernel API `RtlGetVersion` to determine if the response is 19000 or higher (Windows 10 version 2004 or later). |
| T1083 File and Directory Discovery |
MalwareSplatCloak | SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky. |
| T1106 Native API |
MalwareSplatDropper | SplatDropper has utilized hashed Native Windows API calls. |
| T1106 Native API |
MalwarePAKLOG | PAKLOG has used Windows API `SetWindowsHookExW` with `idHook` set to `WH_KEYBOARD_LL` and a custom hook procedure to support its keylogging functions. |
| T1106 Native API |
GroupMustang Panda | Mustang Panda has used various Windows API calls during execution and defense evasion. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDABroadcomEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Sophos Mustang Panda PLUGXTrend Micro Mustang Panda Earth Preta Toneshell February 2025ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1106 Native API |
MalwareSplatCloak | SplatCloak has utilized Native Windows API calls dynamically through `ZwQuerySystemInformation`. |
| T1115 Clipboard Data |
MalwarePAKLOG | PAKLOG has monitored and extracted clipboard contents. |
| T1124 System Time Discovery |
MalwarePAKLOG | PAKLOG has collected a timestamp to log the precise time a key was pressed, formatted as %Y-%m-%d %H:%M:%S. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSplatDropper | SplatDropper has decoded XOR encrypted payload. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareCorKLOG | CorKLOG has decoded XOR encrypted strings. |
| T1204.002 Malicious File |
GroupMustang Panda | Mustang Panda has sent malicious files requiring direct victim interaction to execute. Mustang Panda has also leveraged executable files that display decoy documents to the victim to provide a resemblance of legitimacy with customized themes related to the victim. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019Avira Mustang Panda January 2020CSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022Crowdstrike MUSTANG PANDA June 2018EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google TAG Ukraine Threat Landscape March 2022IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Networks, Unit 42Proofpoint TA416 Europe March 2022Recorded Future REDDELTA July 2020Sophos Mustang Panda PLUGXSophos PlugX September 2022Trend Micro MUSTANG PANDA PUBLOAD HIUPAN SEPTEMBER 2024Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1518.001 Security Software Discovery |
MalwareSplatCloak | SplatCloak has identified drivers of AV solutions by searching for related filenames, keywords and signed certificates. |
| T1543.003 Windows Service |
MalwareCorKLOG | CorKLOG has created a service to establish persistence. |
| T1543.003 Windows Service |
MalwareSplatDropper | SplatDropper has created a service to execute a payload. |
| T1553.002 Code Signing |
MalwareCorKLOG | CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1553.002 Code Signing |
MalwareSplatDropper | SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1553.002 Code Signing |
MalwarePAKLOG | PAKLOG has used legitimate signed binaries such as PACLOUD.exe for follow-on execution of malicious DLLs through DLL Side-Loading. |
| T1553.002 Code Signing |
GroupMustang Panda | Mustang Panda has used valid legitimate digital signatures and certificates to evade detection. |
| T1574.001 DLL |
GroupMustang Panda | Mustang Panda has used a legitimately signed executable to execute a malicious payload within a DLL file. Mustang Panda has abused legitimate executables to side-load malicious DLLs. 2022 November_TrendMicro_Earth Preta_Toneshell_Pubload2025_IBM_PUBLOAD_TONESHELL_HIUPAN_CLAIMLOADER_MUSTANG PANDAAnomali MUSTANG PANDA October 2019BroadcomCSIRT CTI MUSTANG PANDA PUBLOAD TONESHELL JAN 2024Cisco Talos MUSTANG PANDA PLUGX PUBLOAD MAY 2022EclecticIQ Mustang Panda PlugXEset PlugX Korplug Mustang Panda March 2022Google Threat Intelligence Group MUSTANG PANDA PLUGX August 2025IBM MUSTANG PANDA PUBLOAD CLAIMLOADER JUNE 2025Lab52 MUSTANG PANDA PUBLOAD MAY 2023Palo Alto Unit42 STATELY TAURUS TONESHELL September 2023Proofpoint TA416 November 2020Recorded Future REDDELTA July 2020Sophos PlugX September 2022Trend Micro Mustang Panda Earth Preta Toneshell February 2025Unit42 Bookworm Nov2015ZscalerZscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 |
| T1574.001 DLL |
MalwareCorKLOG | CorKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwarePAKLOG | PAKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
| T1574.001 DLL |
MalwareSplatDropper | SplatDropper has leveraged legitimate binaries to conduct DLL side-loading. |
| T1588.003 Code Signing Certificates |
GroupMustang Panda | Mustang Panda has used revoked code signing certificates for its malicious payloads. |
| T1685 Disable or Modify Tools |
MalwareSplatCloak | SplatCloak has identified and disabled API callback features of Windows Defender and Kaspersky. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.