Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Mofang

Also known as: Superman, BRONZE WALKER

Description

Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.(Citation: FOX-IT May 2016 Mofang)

Goals & Targeting

Targeted Sectors

Government
Critical infrastructure
Defense

Targeted Countries / Regions

US
DE
KR
IN

AI Analysis

· 1 week ago

Executive Summary

Mofang is a likely China-based cyber espionage group targeting government, critical infrastructure, defense sectors in the US, Germany, South Korea, India, and others. They have been active since at least May 2012 and primarily use spearphishing techniques with malicious files and links to gain access to sensitive information.

Goals & Targeting

Mofang's strategic objectives involve gathering intelligence from government and critical infrastructure sectors through targeted attacks. They likely aim to support Chinese interests by compromising defense capabilities and technological innovations in the US, Germany, South Korea, and India, reflecting a focus on geopolitical competition.

Enhanced Description

Mofang is a sophisticated cyber espionage group, likely based in China, known for mimicking victim infrastructure during attacks. Since 2012, they have targeted government and critical infrastructure organizations globally, including Myanmar, the US, Germany, South Korea, India, and others. Using tactics such as spearphishing with malicious attachments and links, they seek to collect sensitive information from military, automobile, and weapons industries. Their operations demonstrate a focus on high-value targets to support strategic espionage objectives.

Key Capabilities

  • Spearphishing via attachments and links
  • Distribution of malicious files
  • Use of encrypted/encoded payloads
  • Compression techniques for hiding malware
  • Custom RAT (ShimRat)

MITRE ATT&CK Tactics

Social Engineering
Defense Evasion
Malicious Code Execution

ATT&CK Techniques

T1027.015
T1204.002
T1566.002
T1204.001
T1027.013
T1566.001

Software / Tooling

ShimRat

Campaigns & Victims

Mofang has shown persistent activity since 2012, targeting multiple countries and sectors. Their campaigns often involve spearphishing attacks to infiltrate high-value targets. Notable operations include attacks against Myanmar's government and various global critical infrastructure entities.

IOC Patterns

  • Spear-phishing emails with malicious attachments or links
  • Encrypted/Encoded files in email attachments
  • Compression of malicious files for delivery
  • Malicious domain generation via standard protocols

Recommended Actions

  • Implement multi-layered email security to detect spearphishing attempts.
  • Monitor and decrypt compressed files to identify potential threats.
  • Deploy endpoint detection and response tools to detect ShimRat and similar malware.
  • Segment networks to limit lateral movement post-compromise.
  • Conduct regular security audits focusing on critical sectors.

Suggested Tags

APT
espionage
government
critical-infrastructure

Confidence Assessment

High confidence in group's existence, TTPs, and targeting pattern. Some uncertainty regarding exact origin and current activity level without recent sightings.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. FOX-IT May 2016 Mofang — Yonathan Klijnsma. (2016, May 17). Mofang: A politically motivated information stealing adversary. Retrieved May 12, 2020.

Intel Summary

6

Techniques

2

Tools

0

Campaigns

2

IOCs

0

Observed Data

3

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
espionage
government
critical-infrastructure

Details

MITRE ID
G0103
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--88489675-d216-4884-a98f-49a89fcc1643
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.