logo

Mofang: A politically motivated information stealing adversary

ID: c66eaf94-779e-5882-bc39-8e193d6d943c

STIX ID: report--c66eaf94-779e-5882-bc39-8e193d6d943c

Feed Name: Fox-IT blog

Threat Score
90/100

Date Published: 2016-06-15

Date Updated: 2026-04-27

...
...

Mofang is a likely Chinese, government-affiliated threat actor conducting politically motivated information-stealing campaigns—notably against Myanmar’s government and critical infrastructure—and has targeted multiple countries and sectors using custom tools (ShimRat and ShimRatReporter). The group relies on social engineering rather than exploits for initial access, employs shim-based persistence and built-in privilege elevation in its malware, and operates through reconnaissance, faux infrastructure, and a primary compromise phase to achieve its objectives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.