ATT&CKSoftwareSplatDropper

SplatDropper

S1232

Malware.View on attack.mitre.org

About this malware

SplatDropper is a loader that utilizes native windows API to deliver its payload to the victim environment. SplatDropper has been delivered through RAR archives and used legitimate executable for DLL side-loading. SplatDropper is known to be leveraged by Mustang Panda and was first observed utilized in 2025.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.007
Dynamic API Resolution

SplatDropper has leveraged hashed Windows API calls using a seed value of "131313".

T1027.013
Encrypted/Encoded File

SplatDropper has also utilized XOR encrypted payload.

T1070.009
Clear Persistence

SplatDropper has deleted its malicious payload and removed its own created service to avoid leaving traces of its presence on victim devices.

T1106
Native API

SplatDropper has utilized hashed Native Windows API calls.

T1140
Deobfuscate/Decode Files or Information

SplatDropper has decoded XOR encrypted payload.

T1543.003
Windows Service

SplatDropper has created a service to execute a payload.

T1553.002
Code Signing

SplatDropper has used legitimate signed binaries such as BugSplatHD64.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1574.001
DLL

SplatDropper has leveraged legitimate binaries to conduct DLL side-loading.

Groups that use it1

Campaigns0

None recorded.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.