Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Moafee

Description

Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK. (Citation: Haq 2014)

AI Analysis

· 1 week ago

Executive Summary

Moafee is an active threat actor suspected to operate from Guangdong Province, China. Linked with the DragonOK group due to similar TTPs and tools, Moafee targets various sectors including healthcare, pharmaceuticals, and gaming. They employ custom malware like PoisonIvy and use Binary Padding techniques, posing risks through phishing and supply chain attacks.

Goals & Targeting

Moafee likely targets sectors with high intellectual property value and sensitive data, such as healthcare, pharmaceuticals, and government. Their geographical focus includes the U.S., Japan, South Korea, and other countries, particularly those in which DragonOK has been active. The group's operational goals appear to align with financial gain, industrial espionage, or nation-state interests.

Enhanced Description

Moafee is a Chinese-speaking threat group identified in operations linked to DragonOK via shared tools and TTPs. Known for using custom tools such as PoisonIvy, a Remote Access Trojan (RAT), Moafee engages in Binary Padding attacks, injecting malicious code into legitimate binaries. Their activities suggest targeting sectors rich in intellectual property and sensitive data, including healthcare, pharmaceuticals, and government entities in the U.S., Japan, South Korea, and other regions. Operating since at least 2014, Moafee's campaigns involve spear phishing, supply chain compromise, and custom malware deployment to achieve financial gain, espionage, or strategic objectives.

Key Capabilities

  • Custom malware development
  • Binary Padding technique (T1027.001)
  • Remote Access Trojan deployment (e.g., PoisonIvy)
  • Spear phishing campaigns
  • Supply chain compromise

MITRE ATT&CK Tactics

Adversary Persistence
Credential Access

ATT&CK Techniques

T1027.001
T1203

Software / Tooling

PoisonIvy
Custom Binary Padding toolset

Campaigns & Victims

Moafee's campaigns exhibit a focus on sectors with valuable data, using phishing and malware deployment. While specific campaign details are limited, their activities align with those of DragonOK, indicating a focus on long-term access and strategic data extraction.

IOC Patterns

  • Presence of PoisonIvy RAT
  • Binary Padding anomalies in legitimate software
  • Phishing emails targeting pharmaceutical/gaming sectors

Recommended Actions

  • Monitor for Binary Padding indicators using endpoint detection tools.
  • Implement supply chain security measures to detect and prevent malicious updates.
  • Conduct regular network traffic analysis to identify suspicious domains or IPs linked to Moafee activity.

Suggested Tags

cybercrime
espionage
pharmaceutical-sector
gaming-sector

Confidence Assessment

Medium confidence in inferred activities based on DragonOK links and available TTP data. Limited direct IoC sightings but significant enough contextual evidence to assess their threat level.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Haq 2014 — Haq, T., Moran, N., Scott, M., & Vashisht, S. O. (2014, September 10). The Path to Mass-Producing Cyber Attacks [Blog]. Retrieved November 12, 2014.

Intel Summary

1

Techniques

1

Tools

0

Campaigns

16

IOCs

0

Observed Data

1

Tactics

Tags

cybercrime
espionage
pharmaceutical-sector
gaming-sector

Details

MITRE ID
G0002
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--2e5d3a83-fe00-41a5-9b60-237efc84832f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.