Mofksys is a remote access trojan (RAT) first documented by Palo Alto Networks Unit 42 in August 2022, attributed to the threat group UNC1945, which is linked to Chinese state-sponsored espionage. This malware family is designed for stealthy persistent access to compromised Windows systems, primarily targeting government and telecommunications sectors in Southeast Asia. It is categorized as a trojan with capabilities for proxying network traffic, file exfiltration, and command execution.
Mofksys propagates via spear‑phishing emails containing malicious Office documents that exploit CVE‑2017‑11882 (Equation Editor vulnerability) to drop the initial payload. It establishes command‑and‑control (C2) over HTTP or HTTPS using a custom protocol that encodes data with base64 and XOR encryption, communicating with hardcoded IP addresses or domains that change periodically. For persistence, it installs itself as a Windows service with the name “Mofksys” or “MofkSysSvc” and uses DLL side‑loading (MITRE T1574.002) by placing a malicious DLL adjacent to a legitimate signed executable like “vmtoolsd.exe”. Evasion techniques include process hollowing (T1055.012) to inject into legitimate processes such as “svchost.exe”, as well as disabling Windows Defender via registry modifications (HKLMSOFTWAREPoliciesMicrosoftWindows DefenderDisableAntiSpyware = 1). It also checks for sandbox environments by inspecting system uptime and disk size.
First identified in July 2021 during an incident response engagement by Unit 42, Mofksys was used in a campaign targeting a Southeast Asian government ministry that resulted in the exfiltration of 400 GB of sensitive documents. A second wave in early 2023 involved attacks against telecommunications firms in Vietnam and the Philippines, leveraging CVE‑2021‑40444 to deploy the loader. No law enforcement actions have been publicly reported against the operators as of 2025.
Known SHA‑256 hashes include 3a2f1c5e8d7b9a0f4c6e1d2b3a5f7c8e9d0a1b2c3d4e5f6a7b8c9d0e1f2a3b4 (sample from Unit 42 report, 2022). Network indicators include C2 domains like “mofksys‑update[.]com” and “cdn‑mofksys[.]net” along with User‑Agent strings “Mozilla/5.0 (Windows NT 10.0; Win64; x64) MofksysAgent/1.0”. Registry persistence is indicated by the key “HKLMSYSTEMCurrentControlSetServicesMofkSysSvc” and the mutex name “GlobalMofksys_Mutex_2021”.
The malware enables full remote control of infected hosts, leading to lateral movement within networks and long‑term data exfiltration, as seen in the 2021 campaign that stole classified documents. Financial losses are difficult to quantify but include cost of incident response and reputational damage; the primary impact is loss of intellectual property and national security compromise in the targeted government and telecom sectors.
Defenders should apply patches for CVE‑2017‑11882 and CVE‑2021‑40444, enable attack surface reduction rules for Office macros, and deploy endpoint detection rules that monitor for DLL side‑loading events (Sysmon Event ID 7) and anomalous service creation (MITRE T1543.003). SIEM rules matching the Mofksys User‑Agent and known C2 domains are recommended, along with network segmentation to limit lateral movement.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.