Also known as: Confucius APT
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.(Citation: TrendMicro Confucius APT Feb 2018)(Citation: TrendMicro Confucius APT Aug 2021)(Citation: Uptycs Confucius APT Jan 2021)
Executive Summary
Confucius, an APT group primarily involved in cyber espionage, has targeted military personnel, government organizations, and high-profile individuals in South Asia since at least 2013. Linked to Patchwork, Confucius uses sophisticated techniques including spearphishing, malware deployment, and data exfiltration.
Goals & Targeting
Confucius' strategic objectives appear to focus on intelligence gathering through cyber espionage, targeting individuals and organizations in South Asia that hold valuable political, military, or business-related information. The group's targeting of high-profile personalities suggests an interest in both tactical and strategic intelligence. Typical victims include military personnel, government agencies, and commercial entities.
Enhanced Description
Confucius is a cyber espionage group that has been active since at least 2013, primarily targeting military personnel, high-profile personalities, business persons, and government organizations in South Asia. The group has demonstrated significant operational persistence, with noted similarities to the Patchwork threat group in terms of custom malware code and target selection. Confucius employs a variety of tactics, techniques, and procedures (TTPs) to achieve its objectives, including spearphishing campaigns, malware deployment, and data exfiltration activities. The group's ability to remain undetected for extended periods underscores its sophistication and intent to gather sensitive information from targeted sectors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Confucius has maintained activity across multiple years, with a particular focus on South Asian targets. The group's campaigns often involve initial access via spearphishing emails or malicious links, followed by the deployment of custom malware for persistence and data collection. Notable past operations include targeted attacks against military networks and government institutions. Campaigns typically exhibit a high degree of operational security, with use of polymorphic malware and multiple C2 channels.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the data surrounding Confucius is high due to multiple sources linking it to Patchwork and detailing specific TTPs. However, gaps exist regarding the group's exact APT membership and the full extent of its attack inventory.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
19
Techniques
1
Tools
0
Campaigns
0
IOCs
0
Observed Data
9
Tactics