ATT&CKReferencesTrendMicro Confucius APT Aug 2021

TrendMicro Confucius APT Aug 2021

Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples9

TechniqueUsed byProcedure example
T1041
Exfiltration Over C2 Channel
GroupConfucius

Confucius has exfiltrated stolen files to its C2 server.

T1053.005
Scheduled Task
GroupConfucius

Confucius has created scheduled tasks to maintain persistence on a compromised host.

T1059.001
PowerShell
GroupConfucius

Confucius has used PowerShell to execute malicious files and payloads.

T1083
File and Directory Discovery
GroupConfucius

Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions.

T1105
Ingress Tool Transfer
GroupConfucius

Confucius has downloaded additional files and payloads onto a compromised host following initial access.

T1119
Automated Collection
GroupConfucius

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.

T1204.001
Malicious Link
GroupConfucius

Confucius has lured victims into clicking on a malicious link sent through spearphishing.

T1566.002
Spearphishing Link
GroupConfucius

Confucius has sent malicious links to victims through email campaigns.

T1680
Local Storage Discovery
GroupConfucius

Confucius has used a file stealer that can examine system drives, including those other than the C drive.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.