Mofang__2016__fox-it_mofang_threatreport_tlp-white.pdf
ID: cde0d658-e4cd-4bcc-892d-c262c0a54ad1
STIX ID: report--cde0d658-e4cd-4bcc-892d-c262c0a54ad1
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2016-05-27
Last Modified Date: 2016-05-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mofang is an information-stealing APT tracked by FOX-IT that likely operates out of China with probable government ties; it conducts targeted espionage (notably against Myanmar SEZ-related organizations, government, military and selected industries) using two custom tools, ShimRat (a RAT with persistence via Windows shims and DLL-hijacked AV components) and ShimRatReporter (an environment-mapping reconnaissance tool). The group relies on social engineering for initial compromise, builds faux C2 infrastructure that mimics trusted services, deploys customized payloads configured for local proxies, and the report provides detailed TTPs, timelines, sample hashes, domains/IPs, YARA/Snort rules and host/network IOCs for detection and IR.
