Mofang is a likely China-based cyber espionage group targeting government and critical infrastructure since 2012.
Analyst brief
Mofang (Superman, BRONZE WALKER) is a likely China-based cyber espionage group active since at least May 2012. It targets government and critical infrastructure in Myanmar, along with government and private sector entities in Germany, Singapore, Canada, India, the United States, and South Korea. Key TTPs include gaining initial access via spearphishing (attachments and links) and deploying ShimRat malware, while using encrypted/encoded files and compression for stealth. Defenders should prioritize email security against spearphishing and monitor for infrastructure mimicking that of targeted organizations.
Mofang
SupermanBRONZE WALKER
nation-state
Mofang is a likely China-based cyber espionage group, named for its frequent practice of imitating a victim's infrastructure. This adversary has been observed since at least May 2012 conducting focused attacks against government and critical infrastructure in Myanmar, as well as several other countries and sectors including military, automobile, and weapons industries.
origin (suspected)
🇨🇳China· state-sponsoredattribution confidence: medium (50)
Monitor emails for suspicious attachments and links and educate users to avoid opening unexpected or untrusted attachments and clicking on links from untrusted sources.