ShimRatReporter

MITRE ATT&CK: S0445 View on attack.mitre.org

Aliases: ShimRatReporter

Malware type
spyware, rat
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 12:51:29

Targeted industries: government-and-public-sector defense-and-aerospace manufacturing

Context

ShimRatReporter is a tool used by suspected Chinese adversary Mofang to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as ShimRat) as well as set up faux infrastructure which mimics the adversary's targets. ShimRatReporter has been used in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development.

Detection coverage

  • 304 Sigma rules

Malware & tools used

  • Exfiltration Over C2 Channel (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Software Discovery (attack-pattern)
  • Account Discovery (attack-pattern)
  • Archive Collected Data (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Permission Groups Discovery (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Automated Exfiltration (attack-pattern)
  • Web Protocols (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Automated Collection (attack-pattern)
  • Native API (attack-pattern)
  • Process Discovery (attack-pattern)

Used by threat actors

Reports & references

  • foxitsecurity.files.wordpress.com — Fox It Mofang Threatreport Tlp White (report)
  • MITRE ATT&CK — S0445 (report)

External references