Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Confucius Hacker Group Weaponizes Documents to Infect Windows Systems with AnonDoor Malware

The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies. Over the past year, the group transitioned from document stealers like WooperStealer to sophisticated…

The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies. Over the past year, the group transitioned from document stealers like WooperStealer to sophisticated Python-based backdoors, such as AnonDoor malware.

In December 2024, Confucius utilized improved social engineering tactics. Phishing emails featured weaponized PowerPoint presentations (Document.ppsx) displaying "Corrupted Page" messages. The malicious document contained embedded OLE objects, executing VBScripts from remote infrastructure, which initiated a complex infection chain.

An analysis by FortiGuard Labs shows that the group has weaponized Office documents and malicious LNK files to target Windows systems in South Asia, particularly focusing on organizations in Pakistan. The attack employs DLL side-loading techniques, renaming legitimate Windows executables like fixmapi.exe to Swom.exe for persistence.

Persistence is established through registry modifications under HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load, enabling automatic execution at system startup.

By March 2025, Confucius shifted to malicious LNK files disguised as legitimate documents, such as "Invoice_Jan25.pdf.lnk." These files execute PowerShell commands to download malicious DLLs and decoy PDF documents from remote servers, creating the illusion of legitimate file access while establishing backdoor entry.

The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies.
Sean Avery · Thehackingpost

Downloaded components like Mapistub.dll enhance persistence and prepare Base64-encoded remote host addresses for payload delivery. WooperStealer remains the final payload, configured to exfiltrate various file types including documents, images, and email files.

In August 2025, the group introduced AnonDoor, a Python-based backdoor, marking a significant departure from previous .NET-based tools. This malware sets up execution environments by downloading and configuring Python through the Scoop package manager, creating hidden .pyc files in user directories.

AnonDoor supports extensive command execution capabilities, including screenshot capture, file listing, directory traversal, and credential harvesting from browsers such as Firefox and Edge. It communicates with command-and-control infrastructure using structured data packets and maintains operational security through periodic execution intervals to minimize detection.

Organizations utilizing FortiGate, FortiMail, FortiClient, and FortiEDR solutions benefit from automatic protection against these evolving threats. The malware's modular architecture allows dynamic loading of additional Python modules, expanding functionality as needed.

Advertisement

Confucius continues to target South Asian regions, primarily Pakistan, consistent with its historical operations. FortiGuard Labs has implemented comprehensive detection capabilities, with FortiGuard Antivirus identifying various components, including LNK/Agent variants, MSOffice/Agent samples, and Python/Agent classifications.

The evolution of Confucius highlights the adaptability of state-aligned threat actors and underscores the importance of multi-layered security strategies and ongoing threat intelligence monitoring to defend against advanced espionage activities targeting regional government and defense sectors.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories