ShimRat
MITRE ATT&CK: S0444 View on attack.mitre.org
Aliases: ShimRat
- Malware type
- rat
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-05-27 08:45:05
- Profile updated
- 2026-07-07 12:51:25
Targeted industries: government-and-public-sector defense-and-aerospace manufacturing
Context
ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development. The name "ShimRat" comes from the malware's extensive use of Windows Application Shimming to maintain persistence.
Detection coverage
- 1 YARA rules
- 426 Sigma rules
Malware & tools used
- External Proxy (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Hijack Execution Flow (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Scheduled Transfer (attack-pattern)
- File Deletion (attack-pattern)
- Web Protocols (attack-pattern)
- Windows Command Shell (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Application Shimming (attack-pattern)
- Fallback Channels (attack-pattern)
- Software Packing (attack-pattern)
- Compression (attack-pattern)
- Native API (attack-pattern)
- Windows Service (attack-pattern)
- Network Share Discovery (attack-pattern)
- Data from Local System (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Modify Registry (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
Used by threat actors
- Mofang (threat-actor)
Detection rules
- MALPEDIA_Win_Shimrat_Auto (yara-rule)
Reports & references
- foxitsecurity.files.wordpress.com — Fox It Mofang Threatreport Tlp White (report)
- MITRE ATT&CK — S0444 (report)