SplatDropper is a Windows dropper/loader associated with Mustang Panda activity and used to deploy the SplatCloak kernel driver. It has been observed delivered in a RAR archive such as kb.rar containing the legitimate signed binary BugSplatHD64.exe and a malicious DLL, BugSplat64.dll. Execution occurs through DLL side-loading using the legitimate binary. SplatDropper decrypts the SplatCloak driver with a single-byte XOR key 0x5a, writes the driver to disk, creates a Windows service to execute the payload, waits about five seconds, then stops and removes the service and deletes the driver to reduce traces. Reporting also states that it creates a service to execute a payload and leverages legitimate signed binaries for follow-on execution of malicious DLLs through DLL side-loading. SplatDropper resolves Windows APIs via hashing, using a seed value of "131313". It is directly linked to deployment of SplatCloak, a Windows kernel driver described as disabling EDR-related routines associated with Windows Defender and Kaspersky. High-confidence infection and execution characteristics include use of BugSplatHD64.exe/BugSplat64.dll for side-loading, service creation for payload execution, and post-execution cleanup to minimize artifacts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...SplatCloak, a Windows kernel driver deployed by SplatDropper...
11 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... SplatDropper ... (v1.0) ...
SplatDropper (v1.0)
Dropper component used to deploy the SplatCloak Windows kernel driver for EDR evasion.
Dropper delivered via DLL sideloading that decrypts and writes the SplatCloak kernel driver (single-byte XOR 0x5a), creates a service to run it, waits briefly, then stops/removes the service and deletes the driver to reduce artifacts; resolves Windows APIs by hash.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.