Threat intelligence
- Suspected origin
- India
- First seen
- 2013-01-01 00:00:00
- Motivation
- Information theft and espionage
- TLP
- WHITE
(Trend Micro) Confucius’ campaigns were reportedly active as early as 2013, abusing Yahoo! And Quora forums as part of their command-and-control (C&C) communications. We stumbled upon Confucius, likely from South Asia, while delving into Patchwork’s cyberespionage operations.
Confucius’ operations include deploying bespoke backdoors and stealing files from their victim’s systems with tailored file stealers. The stolen files are then exfiltrated by abusing a cloud service provider. Some of these file stealers specifically target files from USB devices, probably to overcome air-gapped environments.
This group seems to be associated with Patchwork, Dropping Elephant.
Also known as
ConfuciusConfucius APTG0142
Vulnerabilities exploited
Tooling and malware
WarzoneRAT
MITRE ATT&CK techniques
T1119 Automated CollectionT1105 Ingress Tool TransferT1083 File and Directory DiscoveryT1680 Local Storage DiscoveryT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1221 Template Injection
Coverage 1
threat-intel
Chinese and Indian-aligned threat actors have been conducting sustained cyber espionage campaigns targeting Pakistani law enforcement organizations, including the Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad…
