Introduction
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets. TrendMicro Confucius APT Feb 2018 TrendMicro Confucius APT Aug 2021 Uptycs Confucius APT Jan 2021
Activities and Tactics
Information pending cataloguing.
Notable Campaigns
Information pending cataloguing.
Tactics, Techniques, and Procedures (TTPs)
- T1566.002 Spearphishing Link
- T1204.001 Malicious Link
- T1567.002 Exfiltration to Cloud Storage
- T1221 Template Injection
- T1059.005 Visual Basic
- T1566.001 Spearphishing Attachment
- T1203 Exploitation for Client Execution
- T1680 Local Storage Discovery
- T1105 Ingress Tool Transfer
- T1119 Automated Collection
- T1583.006 Web Services
- T1071.001 Web Protocols
- T1041 Exfiltration Over C2 Channel
- T1218.005 Mshta
- T1083 File and Directory Discovery
- T1547.001 Registry Run Keys / Startup Folder
- T1053.005 Scheduled Task
- T1204.002 Malicious File
- T1059.001 PowerShell
ATT&CK technique IDs (denormalized)
- T1041
- T1053.005
- T1059.001
- T1059.005
- T1071.001
- T1083
- T1105
- T1119
- T1203
- T1204.001
- T1204.002
- T1218.005
- T1221
- T1547.001
- T1566.001
- T1566.002
- T1567.002
- T1583.006
- T1680
Notable Indicators of Compromise (IOCs)
No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.
Malware and Tools
- CyberGate:
- Cyber Eye RAT:
- Archelaus Beta:
MITRE ATT&CK Software
Attribution and Evidence
Information pending cataloguing.
References
[1] mitre-attack [2] TrendMicro Confucius APT Feb 2018 Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Groupβs Cyberespionage Operations. Retrieved December 26, 2021. [3] TrendMicro Confucius APT Aug 2021 Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021. [4] Uptycs Confucius APT Jan 2021 Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.