PAKLOG is a Windows keylogger associated with Mustang Panda. It uses high-level Windows APIs to capture keystrokes and monitor clipboard activity, including intercepting Ctrl+V to collect clipboard contents. It implements keylogging with SetWindowsHookExW using WH_KEYBOARD_LL, uses GetForegroundWindow to access the active window, and records contextual information including foreground window text, the full path of the foreground process, and timestamps formatted as %Y-%m-%d %H:%M:%S. Captured keystrokes and clipboard data are obfuscated with a custom character-encoding scheme and written locally to C:\Users\Public\Libraries\record.txt. Reported versions include PAKLOG v1.0. The malware has no built-in exfiltration capability, indicating collected data must be stolen through separate tooling or operator action. PAKLOG has been delivered via RAR archives such as key.rar containing a legitimate signed executable, PACLOUD.exe, and a malicious DLL, pa_lang2.dll; execution occurs through DLL side-loading, and the DLL exports a malicious function named ASH_LANG2_add. Reporting places PAKLOG in Mustang Panda operations alongside CorKLOG, TONESHELL, MQsTTang, Cobalt Strike, Poison Ivy, StarProxy, and SplatCloak. Mustang Panda is described in the source material as a China-aligned threat actor that has targeted governments, military entities, minority groups, and NGOs, primarily in East Asia and also in Europe, with one reported intrusion involving an organization in Myanmar.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...debuting four new attack tools: two keyloggers (PAKLOG and CorKLOG)...
“PAKLOG is a keylogger… monitor keystrokes and clipboard data and employs a custom character encoding scheme to obfuscate the log data.”
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
"PAKLOG has used Windows API SetWindowsHookExW with idHook set to WH_KEYBOARD_LL ... to support its keylogging functions"
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... PAKLOG ... (v1.0) ...
PAKLOG (v1.0)
A keylogger used by Mustang Panda to capture keystrokes and sensitive information from compromised systems.
Keylogger tool used by Mustang Panda to capture keystrokes and exfiltrate sensitive information from targeted systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.