Threat Actor
Moafee
Also known as: Moafee
[Moafee](https://attack.mitre.org/groups/G0002) is a threat group that appears to operate from the Guandong Province of China. Due to overlapping TTPs, including similar custom tools, Moafee is thought to have a direct or indirect relationship with the threat group [DragonOK](https://attack.mitre.org/groups/G0017). (Citation: Haq 2014)
1
Techniques
1
Software
Properties
- stix_id
- intrusion-set--2e5d3a83-fe00-41a5-9b60-237efc84832f
- signal_observed_at
- 2026-09-11T17:54:59+00:00
- type
- intrusion-set
MITRE ATT&CK Techniques (1)
▸
Binary Padding
Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the functiona
Software & Tools (1)
▸
PoisonIvy [malware]
[PoisonIvy](https://attack.mitre.org/software/S0012) is a popular remote access tool (RAT) that has been used by many groups.(Citation: FireEye Poison
Explore this actor's full graph with Ninja Signal