ShimRat

MITRE ATT&CK: S0444 View on attack.mitre.org

Aliases: ShimRat

Malware type
rat
Family
Malware family
Operating systems
windows
Last IoC activity
2026-05-27 08:45:05
Profile updated
2026-07-07 12:51:25

Targeted industries: government-and-public-sector defense-and-aerospace manufacturing

Context

ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development. The name "ShimRat" comes from the malware's extensive use of Windows Application Shimming to maintain persistence.

Detection coverage

  • 1 YARA rules
  • 426 Sigma rules

Malware & tools used

  • External Proxy (attack-pattern)
  • Bypass User Account Control (attack-pattern)
  • Hijack Execution Flow (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Scheduled Transfer (attack-pattern)
  • File Deletion (attack-pattern)
  • Web Protocols (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Application Shimming (attack-pattern)
  • Fallback Channels (attack-pattern)
  • Software Packing (attack-pattern)
  • Compression (attack-pattern)
  • Native API (attack-pattern)
  • Windows Service (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • Data from Local System (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Modify Registry (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)

Used by threat actors

Detection rules

  • MALPEDIA_Win_Shimrat_Auto (yara-rule)

Reports & references

  • foxitsecurity.files.wordpress.com — Fox It Mofang Threatreport Tlp White (report)
  • MITRE ATT&CK — S0444 (report)

External references