PAKLOG has used GetForegroundWindow to access the foreground window. 2 PAKLOG has also captured text from the foreground windows.2
tool
PAKLOG S1233
- Type
- malware
- Platform
- Windows
- Created
- 12 September 2025
- Last modified
- 21 October 2025
PAKLOG is a keylogger known to be leveraged by Mustang Panda and was first observed utilized in 2024. PAKLOG is deployed via a RAR archive (e.g., key.rar), which contains two files: a signed, legitimate binary (PACLOUD.exe) and the malicious PAKLOG DLL (pa_lang2.dll). The PACLOUD.exe binary is used to side-load the PAKLOG DLL which starts with the keylogger functionality.[1]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S1233
PAKLOG has utilized a simple encoding mechanism to encode characters in the buffer.4
PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls.6
PAKLOG has stored the captured data in a file located C:\\Users\\Public\\Libraries\\record.txt.7
PAKLOG has used Windows API SetWindowsHookExW with idHook set to WH_KEYBOARD_LL and a custom hook procedure to support its keylogging functions.8
Standing S1233
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
47th percentile · 53% of 825 ATT&CK software entries have more Enterprise techniques.
53rd percentile · 53% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
5th percentile · 95% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S1233
160 distinct rules cover the 10 techniques recorded for this tool. The 161 technique-to-rule mappings resolve to 160 distinct rules, because one rule can cover several techniques. 135 Sigma · 25 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org