logo

Mustang Panda: PAKLOG, CorKLOG, and SplatCloak

ID: 91386cdb-9cde-5e68-95b9-7926c2aa9e66

STIX ID: report--91386cdb-9cde-5e68-95b9-7926c2aa9e66

Feed Name: Zscaler Security Research Blog

Threat Score
85/100

Date Published: 2025-05-02

Date Updated: 2026-05-01

...
...

Technical analysis identifies Mustang Panda tooling comprising two keyloggers (PAKLOG and CorKLOG) and a kernel-level driver (SplatCloak) dropped by SplatDropper. PAKLOG and CorKLOG capture keystrokes and clipboard data (stored with simple encoding or RC4) and are delivered via RAR archives that use legitimate signed binaries to sideload malicious DLLs; CorKLOG implements persistence via services or scheduled tasks. SplatCloak is a revoked-certificate-signed Windows kernel driver that the dropper writes and runs as a service, and its primary function is to locate and unregister or disable Windows Defender and Kaspersky callback/notification routines to evade EDR; the report includes implementation details (API resolution, hashing, certificate checks), file artifacts, and a certificate thumbprint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.