CorKLOG

S1235

Malware.View on attack.mitre.org

About this malware

CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. CorKLOG is delivered through a RAR archive (e.g., src.rar), which contains two files: an executable (lcommute.exe) and the CorKLOG DLL (mscorsvc.dll). CorKLOG has established persistence on the system by creating services or with scheduled tasks.

Techniques used8

Procedure examples8

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

CorKLOG has encrypted collected contents using RC4. CorKLOG has also utilized XOR encrypted strings.

T1053.005
Scheduled Task

CorKLOG has achieved persistence through the creation of a scheduled task named TableInputServices by using the command `schtasks /create /tn TabletlnputServices /tr /sc minute /mo 10 /f`.

T1056.001
Keylogging

CorKLOG has captured keystrokes.

T1074.001
Local Data Staging

CorKLOG has stored the captured data in an encrypted file using a 48-character RC4 key.

T1140
Deobfuscate/Decode Files or Information

CorKLOG has decoded XOR encrypted strings.

T1543.003
Windows Service

CorKLOG has created a service to establish persistence.

T1553.002
Code Signing

CorKLOG has used legitimate signed binaries such as lcommute.exe for follow-on execution of malicious DLLs through DLL side-loading.

T1574.001
DLL

CorKLOG has leveraged legitimate binaries to conduct DLL side-loading.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Zscaler PAKLOG CorkLog SplatCloak Splatdropper April 2025 Open source
    Sudeep Singh. (2025, April 16). Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2. Retrieved September 12, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.