SplatCloak — Malware Profile
SplatCloak is a malware that disables EDR-related routines used by Windows Defender and Kaspersky to aid in evading detection. SplatCloak has been deployed by SplatDropper and is known to be leveraged by Mustang Panda since 2025.
MITRE ATT&CK techniques (6)
- T1036.001 Invalid Code Signature
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1106 Native API
- T1518.001 Security Software Discovery
- T1685 Disable or Modify Tools