CorKLOG — Malware Profile
CorKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. CorKLOG is delivered through a RAR archive (e.g., src.rar), which contains two files: an executable (lcommute.exe) and the CorKLOG DLL (mscorsvc.dll). CorKLOG has established persistence on the system by creating services or with scheduled tasks.
MITRE ATT&CK techniques (8)
- T1027.013 Encrypted/Encoded File
- T1053.005 Scheduled Task
- T1056.001 Keylogging
- T1074.001 Local Data Staging
- T1140 Deobfuscate/Decode Files or Information
- T1543.003 Windows Service
- T1553.002 Code Signing
- T1574.001 DLL