Confucius

APT / StateG0142 ↗
Techniques (MITRE ATT&CK)19
SourceMITRE ATT&CK
Also known as:Confucius APT

About the group

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity56
Impact: High
T1566.001T1053.005T1547.001T1083T1119ENTRYInitial accessSpearphishingAttachmentEXECExecutionScheduled TaskPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryFile and DirectoryDiscoveryCOLLCollectionAutomatedCollectionEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Confucius uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →