Mofang

MITRE ATT&CK: G0103 View on attack.mitre.org

Aliases: Superman, BRONZE WALKER, Mofang

First seen
2012-05-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Profile updated
2026-07-07 11:53:29

Targeted industries: government-and-public-sector defense-and-aerospace manufacturing

Targeted regions: country_code:mm

Context

Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.

Detection coverage

  • 1 YARA rules
  • 53 Sigma rules

Malware & tools used

  • Spearphishing Link (attack-pattern)
  • Malicious Link (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Malicious File (attack-pattern)
  • Compression (attack-pattern)
  • ShimRatReporter (malware)
  • ShimRat (malware)

Reports & references

  • blog.fox-it.com — Mofang A Politically Motivated Information Stealing Adversary (report)
  • cfr.org — Mofang (report)
  • foxitsecurity.files.wordpress.com — Fox It Mofang Threatreport Tlp White (report)
  • secureworks.com — Bronze Walker (report)
  • MITRE ATT&CK — G0103 (report)

External references