PULSE NAME
Confucius Espionage: From Stealer to Backdoor
WHITE Confucius AlienVault 2025-10-03 Modified: 2025-10-03
26
IOCs
MEDIUM VOLUME
The Confucius group, a long-running cyber-espionage actor operating in South Asia, has evolved its tactics from document stealers to Python-based backdoors. Recent campaigns showcase the group's adaptability and growing sophistication, targeting government agencies, military organizations, and critical industries, particularly in Pakistan. The group has transitioned from using WooperStealer to deploying a Python variant of AnonDoor, demonstrating their ability to pivot between techniques, infrastructure, and malware families. Their attack chain includes weaponized Office documents, malicious LNK files, and multiple malware families, employing obfuscation techniques to evade detection. The group's persistence and rapid adaptation highlight the ongoing threat posed by state-aligned malware campaigns in the region.
Indicators of Compromise (8 / 26 total)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 06b8f395fc6b4fda8d36482a4301a529c21c60c107cbe936e558aef9f56b84f6 2025-10-03
FileHash-SHA256 11391799ae242609304ef71b0efb571f11ac412488ba69d6efc54557447d022f 2025-10-03
FileHash-SHA256 13ca36012dd66a7fa2f97d8a9577a7e71d8d41345ef65bf3d24ea5ebbb7c5ce1 2025-10-03
FileHash-SHA256 24b06b5caad5b09729ccaffa5a43352afd2da2c29c3675b17cae975b7d2a1e62 2025-10-03
FileHash-SHA256 4206ab93ac9781c8367d8675292193625573c2aaacf8feeaddd5b0cc9136d2d1 2025-10-03
FileHash-SHA256 5a0dd2451a1661d12ab1e589124ff8ecd2c2ad55c8f35445ba9cf5e3215f977e 2025-10-03
FileHash-SHA256 8603b9fa8a6886861571fd8400d96a705eb6258821c6ebc679476d1b92dcd09e 2025-10-03
FileHash-SHA256 c91917ff2cc3b843cf9f65e5798cd2e668a93e09802daa50e55a842ba9e505de 2025-10-03