JUST RELEASED: ATT&CK for Industrial Control Systems


Moafee is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group DragonOK. [1]

ID: G0002
Version: 1.0
Created: 31 May 2017
Last Modified: 25 March 2019

Techniques Used

Domain ID Name Use
Enterprise T1009 Binary Padding

Moafee has been known to employ binary padding.[1]


ID Name References Techniques
S0012 PoisonIvy [1] Application Window Discovery, Command-Line Interface, Data from Local System, Data Staged, Input Capture, Modify Existing Service, Modify Registry, New Service, Obfuscated Files or Information, Process Injection, Registry Run Keys / Startup Folder, Remote File Copy, Rootkit, Standard Cryptographic Protocol, Uncommonly Used Port