1200KM / tool
ShimRatReporter — Attack Tool
ShimRatReporter is a tool used by suspected Chinese adversary Mofang to automatically conduct initial discovery. The details from this discovery are used to customize follow-on payloads (such as ShimRat) as well as set up faux infrastructure which mimics the adversary's targets. ShimRatReporter has been used in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: ShimRatReporter
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Mofang · G0103 · Pinned relationship source (relationship--69aa300b-3e31-438c-99bf-4822141046c5)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1020 · Automated Exfiltration · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1069 · Permission Groups Discovery · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1087 · Account Discovery · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1518 · Software Discovery · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Group Enumeration · DC0099
- Image Metadata · DC0028
- Instance Enumeration · DC0075
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Scheduled Job Creation · DC0001
- Script Execution · DC0029
- Service Metadata · DC0041
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.