ShimRat — Malware Profile

ShimRat has been used by the suspected China-based adversary Mofang in campaigns targeting multiple countries and sectors including government, military, critical infrastructure, automobile, and weapons development. The name "ShimRat" comes from the malware's extensive use of Windows Application Shimming to maintain persistence.

MITRE ATT&CK techniques (21)

Attributed threat actors

Read the full analysis on IntelFusions