Confucius

APT / StateG0142
Techniques (MITRE ATT&CK)19
SourceMITRE ATT&CK
Also known as:Confucius APT

Vexday analysis

Confucius é um grupo de espionagem cibernética que atua pelo menos desde 2013, com foco principal em militares, personalidades de alto perfil, empresários e organizações governamentais no Sul da Ásia. Pesquisadores de segurança identificaram semelhanças entre Confucius e o grupo Patchwork, especialmente no código de malware customizado e nos alvos escolhidos por ambos. Catalogado no MITRE ATT&CK como G0142, o grupo possui 19 técnicas documentadas na estrutura e 3 CVEs atribuídas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity55
Impact: High
T1566.001T1053.005T1547.001T1083T1119ENTRYInitial accessSpearphishingAttachmentEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryFile and DirectoryDiscoveryCOLLCollectionAutomatedCollectionEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Confucius uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →