Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
6
techniques
2
software
8,503
corpus matches
profile
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.
techniques
6 attributed · most-instrumented first
software
2 malware & tools attributed
ShimRat
S0444
ShimRatReporter
S0445
read this carefully
8,503 corpus matches is not attribution
That count is indicators which exhibit techniques Mofang is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
showing 30 of 8,503