216.73.217.22

ShimRatReporter

The MITRE Corporation · Published 12/05/2020 23:29 · Modified 27/03/2026 01:07

Essential information

Confidence
100/100
Published
12/05/2020 23:29
Modified
27/03/2026 01:07
Revoked
No
Author / Source
The MITRE Corporation
Related entities
16 attack patterns (mitre), 1 intrusion sets (apt)

Description

[ShimRatReporter](https://attack.mitre.org/software/S0445) is a tool used by suspected Chinese adversary [Mofang](https://attack.mitre.org/groups/G0103) to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as [ShimRat](https://attack.mitre.org/software/S0444)) as well as set up faux infrastructure which mimics the adversary's targets. [ShimRatReporter](https://attack.mitre.org/software/S0445) has been used in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development.(Citation: FOX-IT May 2016 Mofang)

Marking (TLP)

Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.

External references