logo

Confucius APT Android Spyware Targets South Asia

ID: 6a61ae36-bb3e-5e0d-8fe0-65937f85996d

STIX ID: report--6a61ae36-bb3e-5e0d-8fe0-65937f85996d

Feed Name: Cyble Blog

Threat Score
88/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

This report describes Confucius APT's mobile espionage campaign using two Android spyware strains, Hornbill and SunBird, embedded in fake apps to capture and exfiltrate sensitive data (calls, messages, geolocation, media, WhatsApp/BBM/IMO content) from targets in Pakistan and South Asia; SunBird also functions as a RAT with additional capabilities (root commands, scheduled uploads). Researchers recovered ~18GB of exposed exfiltrated data from insecure C2 servers, and the report provides IOCs (SHA1/SHA256 hashes, domains, IPs), a Windows downloader sample analysis, and defensive recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.