Mofang

APT / StateG0103 ↗
Origin🇨🇳 China
Techniques (MITRE ATT&CK)6
SourceMITRE ATT&CK
State sponsor: ChinaAttribution confidence: 50%Target categories: Government, Private sector
Targeted regions: Myanmar · Germany · Singapore · Canada · India · United States · South Korea
Also known as:BRONZE WALKERSuperman

About the group

Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity11
Impact: High
T1566.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionMalicious Link

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 6

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 6

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

sha1_hash3672751b149d961b1626b0aa2501574e1fddce02Shim RATthreatfox
md5_hashcb345182c2482cb19834f6e0bfc0322cShim RATthreatfox
sha256_hashb975fc15637a72cb3452655dc5d7ba2d8230bda8a5752c3047eb4c0851c4c372Shim RATthreatfox
sha256_hash94ffe61fb9619a00d8c1066dc8728df2af733f0b9ca8783a93ecbe1e52e59562Shim RATthreatfox
sha1_hashdd63f54137cd8c2ba7bb43cb6a45db5b2238698cShim RATthreatfox
md5_hashe629a420112f2bcb593f5467a362a91aShim RATthreatfox

Mofang uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →