Confucius

Description

(Trend Micro) Confucius’ campaigns were reportedly active as early as 2013, abusing Yahoo! And Quora forums as part of their command-and-control (C&C) communications. We stumbled upon Confucius, likely from South Asia, while delving into Patchwork’s cyberespionage operations.

Confucius’ operations include deploying bespoke backdoors and stealing files from their victim’s systems with tailored file stealers. The stolen files are then exfiltrated by abusing a cloud service provider. Some of these file stealers specifically target files from USB devices, probably to overcome air-gapped environments.

This group seems to be associated with Patchwork, Dropping Elephant.

Names

NameName-Giver
ConfuciusPalo Alto

Country

Motivation

  • Information theft and espionage

First Seen

2013

Observed Countries

Tools

Operations

Information

Mitre Attack

Other Information

Uuid

5cfcb0a9-c819-4cc2-ad43-36fe47aca3d4

Last Card Change

2022-12-30