SplatCloak

MITRE ATT&CK: S1234 View on attack.mitre.org

Aliases: SplatCloak

Malware type
dropper, trojan
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 15:31:58

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:ru

Context

SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection. SplatCloak has been deployed by SplatDropper and is known to be leveraged by Mustang Panda since 2025.

Detection coverage

  • 226 Sigma rules

Malware & tools used

  • System Information Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Invalid Code Signature (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Used by threat actors

Reports & references

  • zscaler.com — Latest Mustang Panda Arsenal Paklog Corklog And Splatcloak P2 (report)
  • MITRE ATT&CK — S1234 (report)

External references