logo

'Confucius' Cyberspy Evolves From Stealers to Backdoors in Pakistan

ID: f8e8f4c0-d6c8-5e0a-9a1d-fa9b792d4b64

STIX ID: report--f8e8f4c0-d6c8-5e0a-9a1d-fa9b792d4b64

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-10-02

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

FortiGuard Labs researchers report that the Confucius APT (active since 2013 and linked to India-sponsored operations) has transitioned from using infostealers like WooperStealer to deploying Python-based backdoors such as AnonDoor in targeted campaigns against Pakistani government and military targets, employing spear-phishing, malicious LNK/DLL files, PowerShell loaders, MSIL downloaders, heavy obfuscation, and providing IoCs for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.