Confucius

MITRE ATT&CK: G0142 View on attack.mitre.org

Aliases: Confucius APT, Confucius

First seen
2013-01-01 00:00:00
Primary motivation
espionage
Sophistication
intermediate
Resource level
organization
Actor type
nation-state
Related IoCs
1 (1 malicious)
Last IoC activity
2026-03-08 07:37:39
Profile updated
2026-07-07 12:30:42

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:in country_code:pk country_code:bd

Context

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Confucius (G0142). The 1 most recently updated:

TypeIndicatorUpdatedSources
hostname bonimoni.xyz 2026-03-08 1

Detection coverage

  • 2 YARA rules
  • 486 Sigma rules

Malware & tools used

  • Spearphishing Link (attack-pattern)
  • Malicious Link (attack-pattern)
  • Exfiltration to Cloud Storage (attack-pattern)
  • Template Injection (attack-pattern)
  • Visual Basic (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Exploitation for Client Execution (attack-pattern)
  • Local Storage Discovery (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Automated Collection (attack-pattern)
  • Web Services (attack-pattern)
  • Web Protocols (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • Mshta (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Scheduled Task (attack-pattern)
  • Malicious File (attack-pattern)
  • PowerShell (attack-pattern)
  • Hornbill (malware)
  • WarzoneRAT (malware)
  • Sunbird (malware)

Reports & references

  • MITRE ATT&CK — G0142 (report)
  • Trend Micro — Deciphering Confucius Cyberespionage Operations (report)
  • Trend Micro — Confucius Uses Pegasus Spyware Related Lures To Target Pakistani (report)
  • uptycs.com — Confucius Apt Deploys Warzone Rat (report)

External references