PAKLOG — Malware Profile
PAKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. PAKLOG is deployed via a RAR archive (e.g., key.rar), which contains two files: a signed, legitimate binary (PACLOUD.exe) and the malicious PAKLOG DLL (pa_lang2.dll). The PACLOUD.exe binary is used to side-load the PAKLOG DLL which starts with the keylogger functionality.
MITRE ATT&CK techniques (10)
- T1010 Application Window Discovery
- T1027.013 Encrypted/Encoded File
- T1056.001 Keylogging
- T1057 Process Discovery
- T1074.001 Local Data Staging
- T1106 Native API
- T1115 Clipboard Data
- T1124 System Time Discovery
- T1553.002 Code Signing
- T1574.001 DLL