Latest Mustang Panda Arsenal: Toneshell, StarProxy, PAKLOG, CorKLOG, and SplatCloak

April 16, 2025, 9:06 p.m.

Description

Mustang Panda, a threat actor group, has developed new tools including two keyloggers (PAKLOG and CorKLOG) and an EDR evasion driver (SplatCloak). PAKLOG monitors keystrokes and clipboard data, using a custom encoding scheme. CorKLOG captures keystrokes, encrypts data with RC4, and establishes persistence through services or scheduled tasks. SplatCloak disables kernel-level notification callbacks for Windows Defender and Kaspersky drivers, employing obfuscation techniques like control flow flattening and mixed boolean arithmetic. Along with those tools, the group has been observed using updated versions of ToneShell and a new tool called StarProxy. ToneShell, a backdoor, now features changes in its FakeTLS C2 communication protocol and client identifier storage methods. StarProxy, a lateral movement tool, uses the FakeTLS protocol to proxy traffic and facilitate attacker communications.

Date

  • Created: April 16, 2025, 8:35 p.m.
  • Published: April 16, 2025, 8:35 p.m.
  • Modified: April 16, 2025, 9:06 p.m.

Indicators

  • ede116e8f652728773363f6808fa8bbd5af873398e4bb5393c210677fa96a654
  • cf1f057bc8cb25b2d6d0704cef0655ea4d41ea247c51984b25635bd23c8ae109
  • a9b1289383ffe3ee2bd0df96ad6918b9a7e27819e4bc10c3922d8bbd61cbd959
  • a0f42337601429ffda00aa64b8e6102e2470b2388c132f96002f37d40f40d587
  • 91d8b31259d8602539fb6eaa0588d6521bf01299ccd8ed830abfe2ace7aea54d
  • 88e1b73318ba2107c2e70a59064d51e4fecd37ab6175735e43abfa8657d2cd91
  • 63aa30c452e4dc0aa2324ce891da1acfa90ce85476d2dd7ab85ff448f913af5e
  • 649b32f2db7d71cd083e9af4fae2fb3c086f5ed73eac622f427f7fa5d513c605
  • 57e22a93fc31bd299871840864e82fa553e99501af7645102d07dceed2a8ef1a
  • 21e271bde14b62a1c982ea3aefc1c42a7f5b412126e920e7dd4200cbf14fe475
  • befbc4c451721ad8cce0795f82aa0762640644807130bf5d0cba44a1cb194d9c
  • 9c61a53b787bb42b12a3a44151ce1348669b4c745d087fb602df2b28d0fd92b5
  • 86f6d29ef0532236ad180dcf9a4b0c1ac1f8f2ec9cec7a5b312f4e940df7edce
  • 6f3a2913a59309c6b4b38040cfb08a4e04404e6f93215fd72dbc52781d99ff29
  • 6c01b3d9f7929d8d18747cb6feba416e8702f853a303a63ae37af38e95af79cd
  • 3fa4e089bf7bf183d7e746b9eb02b852df5673d7ab39008252e3954fc70d2cba
  • 3a59407db18f575adf956027c8e8af961e1e2ef01d097f6c0a934aeaad45de03
  • 43.254.132.217
  • 43.229.79.163
  • 181.215.246.155
  • 103.13.31.75
  • www.profile-keybord.com
  • www.dest-working.com

Attack Patterns

  • StarProxy
  • SplatCloak
  • CorKLOG
  • PAKLOG
  • ToneShell
  • Mustang Panda

Additional Informations

  • NGO
  • Government
  • Myanmar