Threat group.View on attack.mitre.org
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.
| Technique | Procedure example |
|---|---|
| T1041 Exfiltration Over C2 Channel |
Confucius has exfiltrated stolen files to its C2 server. |
| T1053.005 Scheduled Task |
Confucius has created scheduled tasks to maintain persistence on a compromised host. |
| T1059.001 PowerShell |
Confucius has used PowerShell to execute malicious files and payloads. |
| T1059.005 Visual Basic |
Confucius has used VBScript to execute malicious code. |
| T1071.001 Web Protocols |
Confucius has used HTTP for C2 communications. |
| T1083 File and Directory Discovery |
Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions. |
| T1105 Ingress Tool Transfer |
Confucius has downloaded additional files and payloads onto a compromised host following initial access. |
| T1119 Automated Collection |
Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg. |
| T1203 Exploitation for Client Execution |
Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802. |
| T1204.001 Malicious Link |
Confucius has lured victims into clicking on a malicious link sent through spearphishing. |
| T1204.002 Malicious File |
Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics. |
| T1218.005 Mshta |
Confucius has used mshta.exe to execute malicious VBScript. |
| T1221 Template Injection |
Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit. |
| T1547.001 Registry Run Keys / Startup Folder |
Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence. |
| T1566.001 Spearphishing Attachment |
Confucius has crafted and sent victims malicious attachments to gain initial access. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.