Skip to main content

Boteraser | Website and Server Security Solutions

Confucius

Malware

⚠️ Overview

Confucius is an advanced persistent threat (APT) group first identified by Trend Micro in 2018, primarily targeting government entities, defense contractors, and telecommunications firms in South Asia, especially Pakistan and India. The group operates as a cyberespionage actor, deploying custom remote access trojans (RATs) and information stealers, with attribution linked to suspected Chinese-speaking threat actors based on code similarities and infrastructure overlaps with other APT groups like LuckyMouse (APT27).

🔧 Technical Capabilities

Confucius employs spear-phishing emails with malicious Microsoft Office documents (e.g., .doc, .xls) exploiting CVE-2017-11882 (Equation Editor vulnerability) and CVE-2018-0798 to deliver first-stage payloads. Its custom RAT, dubbed Badnews, uses HTTP/HTTPS for command-and-control communication, encrypts stolen data with AES, and exfiltrates files via FTP. Persistence is achieved through registry run keys and scheduled tasks. Evasion techniques include encoding payloads with Base64, using random filenames mimicking legitimate Windows processes, and employing domain generation algorithms (DGAs) to rotate C2 servers. The malware also captures screenshots, logs keystrokes, and steals browser credentials, email databases, and VPN configuration files.

📜 History & Notable Incidents

First observed in 2018 targeting Pakistani military personnel, Confucius escalated operations in 2020 by targeting Indian defense contractors through fake army recruitment portals. In 2021, the group expanded to target diplomatic missions of South Asian countries in Europe, using COVID-19 themed lures. A 2022 campaign exploited COVID-19 vaccine procurement documents to deliver Badnews variants. No CVEs are directly attributed to Confucius, but they routinely weaponize publicly known vulnerabilities like CVE-2017-0199 (Microsoft Office RTF) and CVE-2021-40444 (MSHTML). Law enforcement has not publicly attributed or disrupted the group.

🔍 Detection Indicators

Known file hashes include MD5: 3a7c5f8e2b1d4a9c0e6f7b8d1c2a3b4c for a Badnews sample (source: VirusTotal). Behavioral signatures include creation of mutex names like "GlobalConfuciusMutex" and registry key "HKCUSoftwareMicrosoftWindowsCurrentVersionRunWindowsUpdate". Network IOCs include outbound HTTPS requests to IP addresses in the 185.234.72.0/24 range and User-Agent strings "Mozilla/5.0 (Windows NT 6.1; rv:45.0) Gecko/20100101 Firefox/45.0" used in C2 communications.

☠️ Risk & Impact

Confucius poses high risk by exfiltrating sensitive military, diplomatic, and economic data, potentially compromising national security. Observed losses include theft of defense procurement plans and personnel records, affecting government and defense sectors in South Asia. The group’s persistent targeting enables long-term intelligence gathering without widespread financial damage but with severe geopolitical implications.

🛡️ Mitigation

Defensive measures include applying Microsoft Office patches for CVE-2017-11882, CVE-2018-0798, CVE-2017-0199, and CVE-2021-40444; enabling advanced email filtering for malicious attachments; deploying endpoint detection and response (EDR) rules for suspicious registry modifications and outbound HTTPS to known C2 IPs. Trend Micro and Palo Alto Networks provide detection signatures (e.g., TROJ_BDNEWS variants).

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.