SplatCloak
MITRE ATT&CK: S1234 View on attack.mitre.org
Aliases: SplatCloak
- Malware type
- dropper, trojan
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 15:31:58
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:ru
Context
SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection. SplatCloak has been deployed by SplatDropper and is known to be leveraged by Mustang Panda since 2025.
Detection coverage
- 226 Sigma rules
Malware & tools used
- System Information Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
- Invalid Code Signature (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Native API (attack-pattern)
- Disable or Modify Tools (attack-pattern)
Used by threat actors
- Mustang Panda (threat-actor)
Reports & references
- zscaler.com — Latest Mustang Panda Arsenal Paklog Corklog And Splatcloak P2 (report)
- MITRE ATT&CK — S1234 (report)