Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Confucius

Also known as: Confucius APT

Description

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.(Citation: TrendMicro Confucius APT Feb 2018)(Citation: TrendMicro Confucius APT Aug 2021)(Citation: Uptycs Confucius APT Jan 2021)

AI Analysis

· 1 week ago

Executive Summary

Confucius, an APT group primarily involved in cyber espionage, has targeted military personnel, government organizations, and high-profile individuals in South Asia since at least 2013. Linked to Patchwork, Confucius uses sophisticated techniques including spearphishing, malware deployment, and data exfiltration.

Goals & Targeting

Confucius' strategic objectives appear to focus on intelligence gathering through cyber espionage, targeting individuals and organizations in South Asia that hold valuable political, military, or business-related information. The group's targeting of high-profile personalities suggests an interest in both tactical and strategic intelligence. Typical victims include military personnel, government agencies, and commercial entities.

Enhanced Description

Confucius is a cyber espionage group that has been active since at least 2013, primarily targeting military personnel, high-profile personalities, business persons, and government organizations in South Asia. The group has demonstrated significant operational persistence, with noted similarities to the Patchwork threat group in terms of custom malware code and target selection. Confucius employs a variety of tactics, techniques, and procedures (TTPs) to achieve its objectives, including spearphishing campaigns, malware deployment, and data exfiltration activities. The group's ability to remain undetected for extended periods underscores its sophistication and intent to gather sensitive information from targeted sectors.

Key Capabilities

  • Spearphishing campaigns
  • Custom malware development
  • Data exfiltration techniques
  • Persistent access operations

MITRE ATT&CK Tactics

Espionage
Credential Access
Exfiltration

ATT&CK Techniques

T1053.005
T1204.002
T1566.002
T1566.001
T1119
T1083
T1218.005
T1583.006
T1041
T1567.002
T1221
T1071.001
T1059.001
T1105
T1204.001
T1680

Software / Tooling

WarzoneRAT

Campaigns & Victims

Confucius has maintained activity across multiple years, with a particular focus on South Asian targets. The group's campaigns often involve initial access via spearphishing emails or malicious links, followed by the deployment of custom malware for persistence and data collection. Notable past operations include targeted attacks against military networks and government institutions. Campaigns typically exhibit a high degree of operational security, with use of polymorphic malware and multiple C2 channels.

IOC Patterns

  • Spearphishing emails targeting military or government personnel
  • Malicious links leading to payloads deployment
  • Scheduled tasks and registry modifications for persistence
  • Exfiltration via cloud storage services
  • Use of custom malware with similarities to Patchwork

Recommended Actions

  • Monitor for scheduled task activity on endpoints.
  • Implement network traffic analysis to detect C2 communications.
  • Conduct regular checks for unauthorized registry entries and startup tasks.
  • Secure high-value assets with multi-factor authentication.
  • Perform endpoint detection and response (EDR) deployments.
  • Educate users about spearphishing tactics and email hygiene.

Suggested Tags

APT
Cyber Espionage
South Asia
Military Targeting

Confidence Assessment

Confidence in the data surrounding Confucius is high due to multiple sources linking it to Patchwork and detailing specific TTPs. However, gaps exist regarding the group's exact APT membership and the full extent of its attack inventory.

ATT&CK Techniques

Execution
6 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. TrendMicro Confucius APT Feb 2018 — Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.
  2. TrendMicro Confucius APT Aug 2021 — Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.
  3. Uptycs Confucius APT Jan 2021 — Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

Intel Summary

19

Techniques

1

Tools

0

Campaigns

0

IOCs

0

Observed Data

9

Tactics

Tags

APT
Government Targeting
Cyber Espionage
South Asia
Military Targeting

Details

MITRE ID
G0142
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--6eded342-33e5-4451-b6b2-e1c62863129f
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.