{
	"id": "c23f53bb-3099-42d0-ace4-cbea09c70b56",
	"created_at": "2026-04-06T00:16:36.190919Z",
	"updated_at": "2026-04-10T03:34:17.250742Z",
	"deleted_at": null,
	"sha1_hash": "d4c57dc6dbd5e5677e5a37f53f94d32e0e302a85",
	"title": "Threat Group Cards: A Threat Actor Encyclopedia",
	"llm_title": "",
	"authors": "",
	"file_creation_date": "0001-01-01T00:00:00Z",
	"file_modification_date": "0001-01-01T00:00:00Z",
	"file_size": 49864,
	"plain_text": "Threat Group Cards: A Threat Actor Encyclopedia\nArchived: 2026-04-05 22:37:13 UTC\n APT group: Moafee\nNames\nMoafee (FireEye)\nG0002 (MITRE)\nCountry China\nMotivation Information theft and espionage\nFirst seen 2014\nDescription\nMoafee is a threat group that appears to operate from the Guandong Province of China.\nDue to overlapping TTPs, including similar custom tools, Moafee is thought to have a\ndirect or indirect relationship with the threat group DragonOK.\n(FireEye) The attack group “Moafee” (named after their command and control\ninfrastructure) appears to operate out of the Guangdong province in China and is known\nto target the governments and military organizations of countries with national interests\nin the South China Sea. The seas in this region have multiple claims of sovereignty and\nhold high significance, as it is the second busiest sea-lane in the world and are known to\nbe rich in resources such as rare earth metals, crude oil, and natural gas. We have also\nobserved the Moafee group target organizations within the US defense industrial base.\nObserved\nSectors: Defense, Government.\nCountries: USA and “countries with national interests in the South China Sea”.\nTools used HTran, Mongall, NewCT2, NFlog, Poison Ivy.\nInformation\nMITRE ATT\u0026CK Last change to this card: 16 August 2025\nDownload this actor card in PDF or JSON format\nSource: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=a89dfb9b-f899-4d5e-b835-1fbb37295660\nhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=a89dfb9b-f899-4d5e-b835-1fbb37295660\nPage 1 of 1",
	"extraction_quality": 1,
	"language": "EN",
	"sources": [
		"ETDA"
	],
	"references": [
		"https://apt.etda.or.th/cgi-bin/showcard.cgi?u=a89dfb9b-f899-4d5e-b835-1fbb37295660"
	],
	"report_names": [
		"showcard.cgi?u=a89dfb9b-f899-4d5e-b835-1fbb37295660"
	],
	"threat_actors": [
		{
			"id": "d7226f71-df4a-405e-9252-f8c4108303ae",
			"created_at": "2022-10-25T15:50:23.325171Z",
			"updated_at": "2026-04-10T02:00:05.413071Z",
			"deleted_at": null,
			"main_name": "Moafee",
			"aliases": [
				"Moafee"
			],
			"source_name": "MITRE:Moafee",
			"tools": [
				"PoisonIvy"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "5ffe400c-6025-44c2-9aa1-7c34a7a192b0",
			"created_at": "2023-01-06T13:46:38.469688Z",
			"updated_at": "2026-04-10T02:00:02.987949Z",
			"deleted_at": null,
			"main_name": "DragonOK",
			"aliases": [
				"Moafee",
				"BRONZE OVERBROOK",
				"G0017",
				"G0002",
				"Shallow Taurus"
			],
			"source_name": "MISPGALAXY:DragonOK",
			"tools": [],
			"source_id": "MISPGALAXY",
			"reports": null
		},
		{
			"id": "7ebda3c6-1789-4d84-97cf-47fb18a0cb28",
			"created_at": "2022-10-25T15:50:23.78829Z",
			"updated_at": "2026-04-10T02:00:05.415039Z",
			"deleted_at": null,
			"main_name": "DragonOK",
			"aliases": [
				"DragonOK"
			],
			"source_name": "MITRE:DragonOK",
			"tools": [
				"PoisonIvy",
				"PlugX"
			],
			"source_id": "MITRE",
			"reports": null
		},
		{
			"id": "c3c08eb0-cced-43ab-b126-fbe0c39a0698",
			"created_at": "2022-10-25T16:07:23.872885Z",
			"updated_at": "2026-04-10T02:00:04.767193Z",
			"deleted_at": null,
			"main_name": "Moafee",
			"aliases": [
				"G0002"
			],
			"source_name": "ETDA:Moafee",
			"tools": [
				"Chymine",
				"Darkmoon",
				"Gen:Trojan.Heur.PT",
				"HTran",
				"HUC Packet Transmit Tool",
				"Mongall",
				"NFlog",
				"NewCT2",
				"Poison Ivy",
				"SPIVY",
				"pivy",
				"poisonivy"
			],
			"source_id": "ETDA",
			"reports": null
		},
		{
			"id": "593dd07d-853c-46cd-8117-e24061034bbf",
			"created_at": "2025-08-07T02:03:24.648074Z",
			"updated_at": "2026-04-10T02:00:03.625859Z",
			"deleted_at": null,
			"main_name": "BRONZE OVERBROOK",
			"aliases": [
				"Danti ",
				"DragonOK ",
				"Samurai Panda ",
				"Shallow Taurus ",
				"Temp.DragonOK "
			],
			"source_name": "Secureworks:BRONZE OVERBROOK",
			"tools": [
				"Aveo",
				"DDKONG",
				"Godzilla Webshell",
				"HelloBridge",
				"IsSpace",
				"NFLog Trojan",
				"PLAINTEE",
				"PlugX",
				"Rambo"
			],
			"source_id": "Secureworks",
			"reports": null
		},
		{
			"id": "340d1673-0678-4e1f-8b75-30da2f65cc80",
			"created_at": "2022-10-25T16:07:23.552036Z",
			"updated_at": "2026-04-10T02:00:04.653109Z",
			"deleted_at": null,
			"main_name": "DragonOK",
			"aliases": [
				"Bronze Overbrook",
				"G0017",
				"Shallow Taurus"
			],
			"source_name": "ETDA:DragonOK",
			"tools": [
				"Agent.dhwf",
				"CT",
				"Chymine",
				"Darkmoon",
				"Destroy RAT",
				"DestroyRAT",
				"FF-RAT",
				"FormerFirstRAT",
				"Gen:Trojan.Heur.PT",
				"HTran",
				"HUC Packet Transmit Tool",
				"HelloBridge",
				"IsSpace",
				"KHRAT",
				"Kaba",
				"Korplug",
				"Mongall",
				"NFlog",
				"NewCT",
				"NfLog RAT",
				"PlugX",
				"Poison Ivy",
				"Rambo",
				"RedDelta",
				"SPIVY",
				"Sogu",
				"SysGet",
				"TIGERPLUG",
				"TVT",
				"Thoper",
				"TidePool",
				"Xamtrav",
				"brebsd",
				"ffrat",
				"pivy",
				"poisonivy"
			],
			"source_id": "ETDA",
			"reports": null
		}
	],
	"ts_created_at": 1775434596,
	"ts_updated_at": 1775792057,
	"ts_creation_date": 0,
	"ts_modification_date": 0,
	"files": {
		"pdf": "https://archive.orkl.eu/d4c57dc6dbd5e5677e5a37f53f94d32e0e302a85.pdf",
		"text": "https://archive.orkl.eu/d4c57dc6dbd5e5677e5a37f53f94d32e0e302a85.txt",
		"img": "https://archive.orkl.eu/d4c57dc6dbd5e5677e5a37f53f94d32e0e302a85.jpg"
	}
}