SplatCloak is a Windows kernel-mode driver associated with Mustang Panda that is used to evade endpoint security monitoring by disabling kernel-level defensive callbacks tied to security products. It has been described as targeting routines used by Microsoft Defender and Kaspersky, including notification and callback mechanisms related to process, thread, image-load, and registry monitoring. The malware also performs security software discovery by identifying antivirus-related drivers through filename, keyword, and code-signing certificate checks before interfering with them.
SplatCloak has been observed as part of a broader Mustang Panda toolchain alongside TONESHELL, StarProxy, PAKLOG, and CorKLOG. It is deployed by a companion component known as SplatDropper, which installs and briefly runs the driver as a service, then removes associated artifacts to reduce forensic traces. Delivery has been observed through DLL sideloading using a legitimate signed executable and a malicious DLL that decrypts and installs the driver. Technical reporting indicates the driver dynamically resolves kernel routines and is intended specifically to impair EDR and antivirus visibility on compromised Windows hosts.
The malware is notable for combining defense evasion with security-product reconnaissance in a kernel driver, enabling follow-on malware to operate with reduced detection. Its use aligns with espionage-oriented intrusions attributed to Mustang Panda, a China-linked threat actor known for targeting governments, military entities, NGOs, and other organizations primarily in Asia and also in Europe.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Details on Exploited Vulnerabilities ... CVE-2021-1675 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve1 = “CVE-2021-1675”
Details on Exploited Vulnerabilities ... CVE-2021-40444 Microsoft Windows ... YARA Rules ... reference = “... PrintNightmare and MSHTML exploits” ... $cve2 = “CVE-2021-40444”
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...and a driver to evade endpoint detection and response (EDR) software (SplatCloak).
“SplatCloak is a tool… that disables kernel-level notification callbacks for four Windows Defender-related drivers and Kaspersky drivers.”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“...employs a custom character encoding scheme to obfuscate the log data.”; “...uses a 48-character long RC4 key to encrypt...” ; “...code obfuscation techniques, including control flow flattening and mixed boolean arithmetic...” ; “...XOR based string obfuscation...”
“Decrypts the kernel driver (SplatCloak) using a single-byte XOR key (0x5a) and writes the result to disk.”
The content includes multiple anti-analysis and environment checks, such as "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks" and "Raspberry Robin performs several system checks as part of anti-analysis mechanisms."
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
The content includes multiple anti-analysis and environment checks, such as "OopsIE checks for information on the CPU fan, temperature, mouse, hard disk, and motherboard as part of its anti-VM checks" and "Raspberry Robin performs several system checks as part of anti-analysis mechanisms."
“SplatCloak… designed to disable EDR-related routines implemented by Windows Defender and Kaspersky…” / “unregister and disable the identified callbacks… removed using the appropriate APIs… CmUnRegisterCallback…”
The content repeatedly describes threat actors and malware disabling or modifying security tools, EDR/AV, logging, firewall rules, integrity checkers, and security settings; e.g., 'Agrius used several mechanisms to try to disable security tools' and 'BlackByte disabled security tools such as Windows Defender and the Raccine anti-ransomware tool during operations.'
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware family referenced as part of Mustang Panda’s tooling; the content does not provide functional details.
... SplatCloak ... (v1.0) ...
SplatCloak (v1.0)
Driver used by Mustang Panda to evade endpoint detection and response (EDR) solutions, enhancing stealth and persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.