SplatDropper — Malware Profile
SplatDropper is a loader that utilizes native windows API to deliver its payload to the victim environment. SplatDropper has been delivered through RAR archives and used legitimate executable for DLL side-loading. SplatDropper is known to be leveraged by Mustang Panda and was first observed utilized in 2025.
MITRE ATT&CK techniques (8)
- T1027.007 Dynamic API Resolution
- T1027.013 Encrypted/Encoded File
- T1070.009 Clear Persistence
- T1106 Native API
- T1140 Deobfuscate/Decode Files or Information
- T1543.003 Windows Service
- T1553.002 Code Signing
- T1574.001 DLL