ATT&CKReferencesUptycs Confucius APT Jan 2021

Uptycs Confucius APT Jan 2021

Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupConfucius

Confucius has used HTTP for C2 communications.

T1105
Ingress Tool Transfer
GroupConfucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1203
Exploitation for Client Execution
GroupConfucius

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.

T1204.002
Malicious File
MalwareWarzoneRAT

WarzoneRAT has relied on a victim to open a malicious attachment within an email for execution.

T1204.002
Malicious File
GroupConfucius

Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics.

T1221
Template Injection
GroupConfucius

Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit.

T1221
Template Injection
MalwareWarzoneRAT

WarzoneRAT has been install via template injection through a malicious DLL embedded within a template RTF in a Word document.

T1547.001
Registry Run Keys / Startup Folder
GroupConfucius

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.

T1566.001
Spearphishing Attachment
MalwareWarzoneRAT

WarzoneRAT has been distributed as a malicious attachment within an email.

T1566.001
Spearphishing Attachment
GroupConfucius

Confucius has crafted and sent victims malicious attachments to gain initial access.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.