Malware.View on attack.mitre.org
CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. CorKLOG is delivered through a RAR archive (e.g., src.rar), which contains two files: an executable (lcommute.exe) and the CorKLOG DLL (mscorsvc.dll). CorKLOG has established persistence on the system by creating services or with scheduled tasks.
| Technique | Procedure example |
|---|---|
| T1027.013 Encrypted/Encoded File |
CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings. |
| T1053.005 Scheduled Task |
CorKLOG has achieved persistence through the creation of a scheduled task named TableInputServices by using the command `schtasks /create /tn TabletlnputServices /tr /sc minute /mo 10 /f`. |
| T1056.001 Keylogging |
CorKLOG has captured keystrokes. |
| T1074.001 Local Data Staging |
CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key. |
| T1140 Deobfuscate/Decode Files or Information |
CorKLOG has decoded XOR encrypted strings. |
| T1543.003 Windows Service |
CorKLOG has created a service to establish persistence. |
| T1553.002 Code Signing |
CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading. |
| T1574.001 DLL |
CorKLOG has leveraged legitimate binaries to conduct DLL side-loading. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.