Mofang

G0103

Threat group.View on attack.mitre.org

About this group

Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.

Techniques used6

Procedure examples6

TechniqueProcedure example
T1027.013
Encrypted/Encoded File

Mofang has encrypted payloads before they are downloaded to victims.

T1027.015
Compression

Mofang has compressed the ShimRat executable within malicious email attachments.

T1204.001
Malicious Link

Mofang's spearphishing emails required a user to click the link to connect to a compromised website.

T1204.002
Malicious File

Mofang's malicious spearphishing attachments required a user to open the file after receiving.

T1566.001
Spearphishing Attachment

Mofang delivered spearphishing emails with malicious documents, PDFs, or Excel files attached.

T1566.002
Spearphishing Link

Mofang delivered spearphishing emails with malicious links included.

Software2

Campaigns0

None recorded.

References1

  1. FOX-IT May 2016 Mofang Open source
    Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.