About the group
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 6
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 6
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
3672751b149d961b1626b0aa2501574e1fddce02Shim RATthreatfoxcb345182c2482cb19834f6e0bfc0322cShim RATthreatfoxb975fc15637a72cb3452655dc5d7ba2d8230bda8a5752c3047eb4c0851c4c372Shim RATthreatfox94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562Shim RATthreatfoxdd63f54137cd8c2ba7bb43cb6a45db5b2238698cShim RATthreatfoxe629a420112f2bcb593f5467a362a91aShim RATthreatfoxMofang uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →