news.mlab.sh
Threat intelligence
Threat actor

Confucius

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
India
First seen
2013-01-01 00:00:00
Motivation
Information theft and espionage
TLP
WHITE

(Trend Micro) Confucius’ campaigns were reportedly active as early as 2013, abusing Yahoo! And Quora forums as part of their command-and-control (C&C) communications. We stumbled upon Confucius, likely from South Asia, while delving into Patchwork’s cyberespionage operations. Confucius’ operations include deploying bespoke backdoors and stealing files from their victim’s systems with tailored file stealers. The stolen files are then exfiltrated by abusing a cloud service provider. Some of these file stealers specifically target files from USB devices, probably to overcome air-gapped environments. This group seems to be associated with Patchwork, Dropping Elephant.

Also known as

ConfuciusConfucius APTG0142

Vulnerabilities exploited

Tooling and malware

WarzoneRAT

MITRE ATT&CK techniques

T1119 Automated CollectionT1105 Ingress Tool TransferT1083 File and Directory DiscoveryT1680 Local Storage DiscoveryT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1221 Template Injection

Coverage 1