Uptime Hamster: 10d 11h 4mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Confucious

Confucious

0 incidentes 0 paises 0 sectores apt IN Ultimo: -
Ver en IntelTracker → APTTrail →
Confucius is an India-linked advanced persistent threat group focused on cyber espionage, active since at least 2013. The group primarily targets military personnel, government organizations, nuclear authorities, and energy sectors in South Asia, particularly in neighboring countries like Pakistan and China. Confucius is often noted for its use of social engineering tactics, including fake chat applications and romance scams, to deliver its malware. The group has shown an evolution in its operational model, shifting from simpler information stealers to more modular and advanced backdoors, while maintaining a consistent focus on intelligence gathering for its suspected state sponsor. The group operates under the name Confucius, though it has also been referred to as Confucious and by its MITRE ATT&CK ID G0142. It is sometimes noted for similarities with the Patchwork group, though they are generally considered distinct entities.
Tecnicas MITRE
T1566 -, T1027 -, T1005 -, T1204.002 -
CVEs relacionadas
CVE-2023-34044, CVE-2023-20870, CVE-2023-20869
Tipo
apt
Pais origen
IN
Motivacion
-
Impacto
8
Actualizado
Mon, 05 Ja

Sectores objetivo (SOCRadar)

Energy & Utilities Public AdministrationSpace & DefenseNational Security&International AffairsNational Security