'Confucius' Cyberspy Evolves From Stealers to Backdoors in Pakistan
ID: f8e8f4c0-d6c8-5e0a-9a1d-fa9b792d4b64
STIX ID: report--f8e8f4c0-d6c8-5e0a-9a1d-fa9b792d4b64
Feed Name: Dark Reading
Date Published: 2025-10-02
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
FortiGuard Labs researchers report that the Confucius APT (active since 2013 and linked to India-sponsored operations) has transitioned from using infostealers like WooperStealer to deploying Python-based backdoors such as AnonDoor in targeted campaigns against Pakistani government and military targets, employing spear-phishing, malicious LNK/DLL files, PowerShell loaders, MSIL downloaders, heavy obfuscation, and providing IoCs for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
