Confucius
MITRE ATT&CK: G0142 View on attack.mitre.org
Aliases: Confucius APT, Confucius
- First seen
- 2013-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- organization
- Actor type
- nation-state
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-03-08 07:37:39
- Profile updated
- 2026-07-07 12:30:42
Targeted industries: defense-and-aerospace government-and-public-sector
Targeted regions: country_code:in country_code:pk country_code:bd
Context
Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Confucius (G0142). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | bonimoni.xyz | 2026-03-08 | 1 |
Detection coverage
- 2 YARA rules
- 486 Sigma rules
Malware & tools used
- Spearphishing Link (attack-pattern)
- Malicious Link (attack-pattern)
- Exfiltration to Cloud Storage (attack-pattern)
- Template Injection (attack-pattern)
- Visual Basic (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Exploitation for Client Execution (attack-pattern)
- Local Storage Discovery (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Automated Collection (attack-pattern)
- Web Services (attack-pattern)
- Web Protocols (attack-pattern)
- Exfiltration Over C2 Channel (attack-pattern)
- Mshta (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Scheduled Task (attack-pattern)
- Malicious File (attack-pattern)
- PowerShell (attack-pattern)
- Hornbill (malware)
- WarzoneRAT (malware)
- Sunbird (malware)
Reports & references
- MITRE ATT&CK — G0142 (report)
- Trend Micro — Deciphering Confucius Cyberespionage Operations (report)
- Trend Micro — Confucius Uses Pegasus Spyware Related Lures To Target Pakistani (report)
- uptycs.com — Confucius Apt Deploys Warzone Rat (report)