logo

Mofang__2016__fox-it_mofang_threatreport_tlp-white.pdf

ID: cde0d658-e4cd-4bcc-892d-c262c0a54ad1

STIX ID: report--cde0d658-e4cd-4bcc-892d-c262c0a54ad1

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2016-05-27

Last Modified Date: 2016-05-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Mofang is an information-stealing APT tracked by FOX-IT that likely operates out of China with probable government ties; it conducts targeted espionage (notably against Myanmar SEZ-related organizations, government, military and selected industries) using two custom tools, ShimRat (a RAT with persistence via Windows shims and DLL-hijacked AV components) and ShimRatReporter (an environment-mapping reconnaissance tool). The group relies on social engineering for initial compromise, builds faux C2 infrastructure that mimics trusted services, deploys customized payloads configured for local proxies, and the report provides detailed TTPs, timelines, sample hashes, domains/IPs, YARA/Snort rules and host/network IOCs for detection and IR.