LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G0142: Confucius

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.[1][2][3]

EnterpriseG0142GroupObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Confucius matters because ATT&CK describes it as a long-running cyber espionage group focused on South Asian military personnel, high-profile individuals, business persons, and government organizations. For leaders, the decision value is not the name alone; it is the pattern of targeted social engineering, client-side execution, Windows persistence, remote access tooling, Android malware relationships, and data collection/exfiltration techniques that can affect sensitive communications and continuity of trusted operations.

Executive priority

Prioritize this as a targeted-espionage readiness question: can the organization prove it can detect and investigate spearphishing attachments or links, malicious documents, PowerShell/VB/mshta execution, scheduled tasks or Run Key persistence, RAT activity, and suspicious data movement to C2 or cloud storage? This is especially relevant for organizations with South Asia exposure, government or defense adjacency, executives, or mobile-device risk. Budget and audit conversations should focus on evidence quality across email, endpoint, identity, network, cloud storage, and mobile management rather than assuming a single control will cover the behavior.

Technical view

ATT&CK does not provide a dedicated detection section for Confucius, so SOC and IR teams should validate coverage through the related software and techniques. Enterprise relationships include WarzoneRAT on Windows and techniques spanning spearphishing attachment/link, malicious file/link execution, exploitation for client execution, PowerShell, Visual Basic, mshta, template injection, scheduled tasks, Registry Run Keys/Startup Folder, file/local storage discovery, automated collection, ingress tool transfer, web-protocol C2, exfiltration over C2, exfiltration to cloud storage, and use of web services. Mobile relationships include Android malware families Hornbill and Sunbird. Detection engineering should map these behaviors into end-to-end intrusion chains rather than isolated alerts.

Likely telemetry

  • Email security logs for targeted attachments, links, sender metadata, URL rewriting/click events, and attachment detonation results.
  • Endpoint process, command-line, script, module, and parent-child execution telemetry for PowerShell, Visual Basic, mshta.exe, document-spawned processes, and downloaded payloads.
  • Windows persistence telemetry for scheduled task creation/modification and Registry Run Key or Startup Folder changes.
  • File system and discovery telemetry showing unusual enumeration of files, directories, local storage, and staged collection activity.
  • Network telemetry for HTTP/S or other web-protocol command-and-control patterns, unusual outbound connections, and tool transfer activity.

Detection direction

  • Build correlation around the sequence: targeted email or link exposure, user execution, script or LOLBin activity, persistence, discovery/collection, C2, and exfiltration.
  • Tune detections for common false positives in PowerShell, scheduled tasks, Registry Run Keys, mshta.exe, cloud storage, and web traffic by using baselines for administrative tools, approved automation, and sanctioned storage services.
  • Validate that malicious document behaviors are visible, including template injection indicators and document applications spawning interpreters, mshta, or download utilities.
  • Review whether mobile telemetry exists at all; Android malware relationships create a coverage gap if the SOC only monitors traditional enterprise endpoints.
  • Use the related techniques to drive threat hunts, but avoid treating the group name as proof of attribution without local forensic evidence and intelligence corroboration.

Mitigation priorities

  • Start with phishing resilience: email filtering, attachment and link inspection, user reporting workflows, and rapid takedown/blocking procedures for malicious links.
  • Reduce client-execution risk through timely patching of user-facing applications and hardening of document handling, scripting, and trusted Windows utilities where business-compatible.
  • Strengthen endpoint controls for script execution, suspicious child processes, scheduled task creation, Run Key persistence, and unauthorized tool transfer.
  • Constrain and monitor outbound web traffic and cloud storage use, with clear allowlists or governance for sanctioned services where feasible.
  • Ensure sensitive roles and high-risk users have stronger identity controls, incident playbooks, and mobile-device protections, especially where Android exposure is material.
Additional notes and limits

The strongest defender value comes from using Confucius as an intelligence-informed coverage test across social engineering, endpoint execution, persistence, collection, C2, exfiltration, and Android mobile risk. Similarities to Patchwork are noted by security researchers in the official description, but that should not be used as attribution without additional evidence.

The supplied ATT&CK group object has no official detection text, no group-level platforms or tactics, and only relationship-derived technique/software context. This take does not assert current activity, customer exposure, or guaranteed detection. Local targeting, telemetry quality, control configuration, and incident evidence are required to determine relevance.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Confucius

Confucius is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between Confucius and Patchwork, particularly in their respective custom malware code and targets.[1][2][3]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

19 rows
DomainIDNameRelationship / procedure
EnterpriseT1566.002Spearphishing LinkSub-technique

Confucius has sent malicious links to victims through email campaigns.[2]

EnterpriseT1204.001Malicious LinkSub-technique

Confucius has lured victims into clicking on a malicious link sent through spearphishing.[2]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Confucius has exfiltrated victim data to cloud storage service accounts.[1]

EnterpriseT1221Template Injection

Confucius has used a weaponized Microsoft Word document with an embedded RTF exploit.[3]

EnterpriseT1059.005Visual BasicSub-technique

Confucius has used VBScript to execute malicious code.[1]

EnterpriseT1566.001Spearphishing AttachmentSub-technique

Confucius has crafted and sent victims malicious attachments to gain initial access.[3]

EnterpriseT1203Exploitation for Client Execution

Confucius has exploited Microsoft Office vulnerabilities, including CVE-2015-1641, CVE-2017-11882, and CVE-2018-0802.[3][1]

EnterpriseT1680Local Storage Discovery

Confucius has used a file stealer that can examine system drives, including those other than the C drive.[2]

EnterpriseT1105Ingress Tool Transfer

Confucius has downloaded additional files and payloads onto a compromised host following initial access.[3][2]

EnterpriseT1119Automated Collection

Confucius has used a file stealer to steal documents and images with the following extensions: txt, pdf, png, jpg, doc, xls, xlm, odp, ods, odt, rtf, ppt, xlsx, xlsm, docx, pptx, and jpeg.[2]

EnterpriseT1583.006Web ServicesSub-technique

Confucius has obtained cloud storage service accounts to host stolen data.[1]

EnterpriseT1071.001Web ProtocolsSub-technique

Confucius has used HTTP for C2 communications.[3]

EnterpriseT1041Exfiltration Over C2 Channel

Confucius has exfiltrated stolen files to its C2 server.[2]

EnterpriseT1218.005MshtaSub-technique

Confucius has used mshta.exe to execute malicious VBScript.[1]

EnterpriseT1083File and Directory Discovery

Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions.[2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Confucius has dropped malicious files into the startup folder `%AppData%\Microsoft\Windows\Start Menu\Programs\Startup` on a compromised host in order to maintain persistence.[3]

EnterpriseT1053.005Scheduled TaskSub-technique

Confucius has created scheduled tasks to maintain persistence on a compromised host.[2]

EnterpriseT1204.002Malicious FileSub-technique

Confucius has lured victims to execute malicious attachments included in crafted spearphishing emails related to current topics.[3]

EnterpriseT1059.001PowerShellSub-technique

Confucius has used PowerShell to execute malicious files and payloads.[2]

Associated objects

Groups, software, and campaigns

MalwareEnterprise

S0670: WarzoneRAT

WarzoneRAT is a malware-as-a-service remote access tool (RAT) written in C++ that has been publicly available for purchase since at least late 2018.[1][2]

Windows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
43e06974ced05192...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle43e06974ced0…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  2. [2]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  3. [3]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  4. [4]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  5. [5]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  6. [6]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  7. [7]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  8. [8]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  9. [9]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  10. [10]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  11. [11]
    mitre-attackG0142
    Open source URL
  12. [12]
    mitre-attackG0142
    Open source URL
  13. [13]
    mitre-attackG0142
    Open source URL
  14. [14]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  15. [15]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  16. [16]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  17. [17]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  18. [18]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  19. [19]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  20. [20]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  21. [21]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  22. [22]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  23. [23]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  24. [24]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  25. [25]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  26. [26]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  27. [27]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  28. [28]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  29. [29]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  30. [30]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  31. [31]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  32. [32]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  33. [33]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  34. [34]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  35. [35]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  36. [36]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  37. [37]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  38. [38]
    Check Point Warzone Feb 2020

    Harakhavik, Y. (2020, February 3). Warzone: Behind the enemy lines. Retrieved December 17, 2021.

    Open source URL
  39. [39]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  40. [40]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  41. [41]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  42. [42]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  43. [43]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  44. [44]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  45. [45]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  46. [46]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  47. [47]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  48. [48]
    TrendMicro Confucius APT Feb 2018

    Lunghi, D and Horejsi, J. (2018, February 13). Deciphering Confucius: A Look at the Group's Cyberespionage Operations. Retrieved December 26, 2021.

    Open source URL
  49. [49]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  50. [50]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  51. [51]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  52. [52]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
  53. [53]
    Uptycs Confucius APT Jan 2021

    Uptycs Threat Research Team. (2021, January 12). Confucius APT deploys Warzone RAT. Retrieved December 17, 2021.

    Open source URL
  54. [54]
    TrendMicro Confucius APT Aug 2021

    Lunghi, D. (2021, August 17). Confucius Uses Pegasus Spyware-related Lures to Target Pakistani Military. Retrieved December 26, 2021.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.