Mofang
MITRE ATT&CK: G0103 View on attack.mitre.org
Aliases: Superman, BRONZE WALKER, Mofang
- First seen
- 2012-05-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Profile updated
- 2026-07-07 11:53:29
Targeted industries: government-and-public-sector defense-and-aerospace manufacturing
Targeted regions: country_code:mm
Context
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.
Detection coverage
- 1 YARA rules
- 53 Sigma rules
Malware & tools used
- Spearphishing Link (attack-pattern)
- Malicious Link (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Malicious File (attack-pattern)
- Compression (attack-pattern)
- ShimRatReporter (malware)
- ShimRat (malware)
Reports & references
- blog.fox-it.com — Mofang A Politically Motivated Information Stealing Adversary (report)
- cfr.org — Mofang (report)
- foxitsecurity.files.wordpress.com — Fox It Mofang Threatreport Tlp White (report)
- secureworks.com — Bronze Walker (report)
- MITRE ATT&CK — G0103 (report)