CorKLOG is a Windows keylogger associated with Mustang Panda activity. It is designed to capture keystrokes and store the collected data locally in encrypted form, using RC4 with a 48-character key. The malware has been observed establishing persistence through either creation of a Windows service or a scheduled task, enabling repeated execution on compromised hosts. CorKLOG also employs defense-evasion and execution-hijacking tradecraft by abusing DLL side-loading with legitimate signed binaries to launch malicious code. Additional reported obfuscation includes XOR-encoded strings that are decoded at runtime. CorKLOG appears to function primarily as a collection component for credential and user-activity monitoring, with staged data intended for later retrieval or exfiltration by other tooling rather than confirmed built-in exfiltration logic. It has been documented as part of a broader Mustang Panda toolset used in espionage-oriented intrusions targeting organizations including government, military, NGO, and regional interests in Asia.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...debuting four new attack tools: two keyloggers (PAKLOG and CorKLOG)...
CorKLOG (CorkLOG) is another keylogger designed to capture keystrokes, storing the captured data in an encrypted file using a 48-character RC4 key... establishes persistence on the system by creating services or scheduled tasks.
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
“Sandworm Team leveraged Scheduled Tasks through a Group Policy Object (GPO) to execute CaddyWiper at a predetermined time.” / “APT29 used scheduler and schtasks to create new tasks on remote host as part of their lateral movement… updating an existing legitimate task to execute their tools and then returned the scheduled task to its original configuration.”
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
APT-C-36 has used a macro function to set scheduled tasks, disguised as those used by Google.
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
... CorKLOG ... (v1.0) ...
CorKLOG (v1.0)
Windows keylogger that captures keystrokes, stages collected data locally, and encrypts it (RC4; also uses XOR-obfuscated strings). Establishes persistence via Windows service creation and scheduled tasks, and uses DLL side-loading (including via legitimate signed binaries such as lcommute.exe) for execution.
A keylogger used by Mustang Panda for espionage and credential theft.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.