ATT&CKReferencesTrendMicro Confucius APT Feb 2018

TrendMicro Confucius APT Feb 2018

Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1059.005
Visual Basic
GroupConfucius

Confucius has used VBScript to execute malicious code.

T1203
Exploitation for Client Execution
GroupConfucius

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.

T1218.005
Mshta
GroupConfucius

Confucius has used mshta.exe to execute malicious VBScript.

T1567.002
Exfiltration to Cloud Storage
GroupConfucius

Confucius has exfiltrated victim data to cloud storage service accounts.

T1583.006
Web Services
GroupConfucius

Confucius has obtained cloud storage service accounts to host stolen data.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.