Mofang is a likely China-based cyber espionage threat actor active since at least 2012. The group is known for imitating victim infrastructure and has conducted focused intrusion activity against government and critical infrastructure targets in Myanmar, while also targeting organizations in other countries. Reported victim sectors include government, military and defense, automobiles, and weapons-related industries. Mofang has used spearphishing as a primary initial access vector, delivering malicious links as well as weaponized attachments such as documents, PDFs, and Excel files. Its operations have relied on user execution of malicious files after delivery. The group has also used compressed and encrypted payload delivery, including compressed malware within email attachments and encrypted payloads prior to download, reflecting tradecraft aimed at evasion and staged malware delivery. Mofang is assessed as an espionage-oriented actor rather than a financially motivated or extortion-focused group. No ransomware or extortion activity is directly supported. Known naming in the available reporting centers on Mofang itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in detection annotations for Ghostscript exploitation; no specific campaign activity is described in this reference.
Listed as a threat actor associated with the malicious file execution technique detected by this analytic.
Listed in the detection annotations as a threat actor associated with EFI volume mounting / installation-related behavior.
Referenced as a threat actor associated with spearphishing attachment activity involving malicious file execution and potential credential capture via UDL files.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.