Moafee
MITRE ATT&CK: G0002 View on attack.mitre.org
Aliases: Moafee
- Primary motivation
- espionage
- Sophistication
- expert
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 11:51:22
Targeted industries: defense-and-aerospace government-and-public-sector technology-and-telecommunications
Context
Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK.
Detection coverage
- 1 YARA rules
- 3 Sigma rules
Malware & tools used
- Binary Padding (attack-pattern)
- PoisonIvy (malware)
Related threat objects
- DragonOK (threat-actor)
Reports & references
- MITRE ATT&CK — G0002 (report)
- Mandiant — The Path To Mass Producing Cyber Attacks (report)