ATT&CKGroupsConfucius

Confucius

G0142

Threat group.View on attack.mitre.org

About this group

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.

Techniques used19

Procedure examples19

TechniqueProcedure example
T1041
Exfiltration Over C2 Channel

Confucius has exfiltrated stolen files to its C2 server.

T1053.005
Scheduled Task

Confucius has created scheduled tasks to maintain persistence on a compromised host.

T1059.001
PowerShell

Confucius has used PowerShell to execute malicious files and payloads.

T1059.005
Visual Basic

Confucius has used VBScript to execute malicious code.

T1071.001
Web Protocols

Confucius has used HTTP for C2 communications.

T1083
File and Directory Discovery

Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions.

T1105
Ingress Tool Transfer

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1119
Automated Collection

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

T1203
Exploitation for Client Execution

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.

T1204.001
Malicious Link

Confucius has lured victims into clicking on a malicious link sent through spearphishing.

T1204.002
Malicious File

Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics.

T1218.005
Mshta

Confucius has used mshta.exe to execute malicious VBScript.

T1221
Template Injection

Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit.

T1547.001
Registry Run Keys / Startup Folder

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.

T1566.001
Spearphishing Attachment

Confucius has crafted and sent victims malicious attachments to gain initial access.

View all 19 procedure examples

Software1

Campaigns0

None recorded.

References3

  1. TrendMicro Confucius APT Aug 2021 Open source
    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.
  2. TrendMicro Confucius APT Feb 2018 Open source
    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.
  3. Uptycs Confucius APT Jan 2021 Open source
    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.