CorKLOG is a Windows keylogger associated with Mustang Panda. It captures keystrokes and stores the collected data locally in an encrypted file using RC4 with a 48-character key; reported analyses include the key value fkpioefpoea$@^Tf0-0-gepwf09IJGEJ0IFAPKO456SG894E. CorKLOG establishes persistence either by creating a Windows service or, when not elevated, by creating a scheduled task. Reported task names include TabletInputServices / TabletlnputServices, with one analysis noting use of schtasks to create a task that runs every 10 minutes and then executes it immediately. CorKLOG also uses XOR-encrypted strings and decodes them at runtime, and it leverages DLL side-loading via legitimate signed binaries; lcommute.exe is specifically cited as a signed binary used for follow-on execution of malicious DLLs. Delivery has been described via a RAR archive containing lcommute.exe and a malicious DLL, although one analyzed sample reportedly had a sideloading filename mismatch that prevented the intended DLL load. The malware lacks built-in exfiltration capability in the cited reporting, implying captured data must be collected by other tooling. CorKLOG is part of a broader Mustang Panda toolset that also includes PAKLOG, TONESHELL, MQsTTang, Cobalt Strike, Poison Ivy, StarProxy, and SplatCloak. High-confidence behaviors directly mentioned in the source include keystroke capture, local encrypted staging of captured data, persistence through services or scheduled tasks, and DLL side-loading.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...debuting four new attack tools: two keyloggers (PAKLOG and CorKLOG)...
CorKLOG (CorkLOG) is another keylogger designed to capture keystrokes, storing the captured data in an encrypted file using a 48-character RC4 key... establishes persistence on the system by creating services or scheduled tasks.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... CorKLOG ... (v1.0) ...
CorKLOG (v1.0)
Windows keylogger that captures keystrokes, stages collected data locally, and encrypts it (RC4; also uses XOR-obfuscated strings). Establishes persistence via Windows service creation and scheduled tasks, and uses DLL side-loading (including via legitimate signed binaries such as lcommute.exe) for execution.
A keylogger used by Mustang Panda for espionage and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.