Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK. (Citation: Haq 2014)
Executive Summary
Moafee is an active threat actor suspected to operate from Guangdong Province, China. Linked with the DragonOK group due to similar TTPs and tools, Moafee targets various sectors including healthcare, pharmaceuticals, and gaming. They employ custom malware like PoisonIvy and use Binary Padding techniques, posing risks through phishing and supply chain attacks.
Goals & Targeting
Moafee likely targets sectors with high intellectual property value and sensitive data, such as healthcare, pharmaceuticals, and government. Their geographical focus includes the U.S., Japan, South Korea, and other countries, particularly those in which DragonOK has been active. The group's operational goals appear to align with financial gain, industrial espionage, or nation-state interests.
Enhanced Description
Moafee is a Chinese-speaking threat group identified in operations linked to DragonOK via shared tools and TTPs. Known for using custom tools such as PoisonIvy, a Remote Access Trojan (RAT), Moafee engages in Binary Padding attacks, injecting malicious code into legitimate binaries. Their activities suggest targeting sectors rich in intellectual property and sensitive data, including healthcare, pharmaceuticals, and government entities in the U.S., Japan, South Korea, and other regions. Operating since at least 2014, Moafee's campaigns involve spear phishing, supply chain compromise, and custom malware deployment to achieve financial gain, espionage, or strategic objectives.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Moafee's campaigns exhibit a focus on sectors with valuable data, using phishing and malware deployment. While specific campaign details are limited, their activities align with those of DragonOK, indicating a focus on long-term access and strategic data extraction.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Medium confidence in inferred activities based on DragonOK links and available TTP data. Limited direct IoC sightings but significant enough contextual evidence to assess their threat level.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
1
Tools
0
Campaigns
16
IOCs
0
Observed Data
1
Tactics