Confucius Hacker Group Weaponizes Documents to Infect Windows Systems with AnonDoor Malware
The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies. Over the past year, the group transitioned from document stealers like WooperStealer to sophisticated…
The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies. Over the past year, the group transitioned from document stealers like WooperStealer to sophisticated Python-based backdoors, such as AnonDoor malware.
In December 2024, Confucius utilized improved social engineering tactics. Phishing emails featured weaponized PowerPoint presentations (Document.ppsx) displaying "Corrupted Page" messages. The malicious document contained embedded OLE objects, executing VBScripts from remote infrastructure, which initiated a complex infection chain.
An analysis by FortiGuard Labs shows that the group has weaponized Office documents and malicious LNK files to target Windows systems in South Asia, particularly focusing on organizations in Pakistan. The attack employs DLL side-loading techniques, renaming legitimate Windows executables like fixmapi.exe to Swom.exe for persistence.
Persistence is established through registry modifications under HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load, enabling automatic execution at system startup.
By March 2025, Confucius shifted to malicious LNK files disguised as legitimate documents, such as "Invoice_Jan25.pdf.lnk." These files execute PowerShell commands to download malicious DLLs and decoy PDF documents from remote servers, creating the illusion of legitimate file access while establishing backdoor entry.
The Confucius hacking group, known for cyber-espionage activities with suspected state-sponsored affiliations, has advanced its attack strategies.
Downloaded components like Mapistub.dll enhance persistence and prepare Base64-encoded remote host addresses for payload delivery. WooperStealer remains the final payload, configured to exfiltrate various file types including documents, images, and email files.
In August 2025, the group introduced AnonDoor, a Python-based backdoor, marking a significant departure from previous .NET-based tools. This malware sets up execution environments by downloading and configuring Python through the Scoop package manager, creating hidden .pyc files in user directories.
AnonDoor supports extensive command execution capabilities, including screenshot capture, file listing, directory traversal, and credential harvesting from browsers such as Firefox and Edge. It communicates with command-and-control infrastructure using structured data packets and maintains operational security through periodic execution intervals to minimize detection.
Organizations utilizing FortiGate, FortiMail, FortiClient, and FortiEDR solutions benefit from automatic protection against these evolving threats. The malware's modular architecture allows dynamic loading of additional Python modules, expanding functionality as needed.
Confucius continues to target South Asian regions, primarily Pakistan, consistent with its historical operations. FortiGuard Labs has implemented comprehensive detection capabilities, with FortiGuard Antivirus identifying various components, including LNK/Agent variants, MSOffice/Agent samples, and Python/Agent classifications.
The evolution of Confucius highlights the adaptability of state-aligned threat actors and underscores the importance of multi-layered security strategies and ongoing threat intelligence monitoring to defend against advanced espionage activities targeting regional government and defense sectors.
Based on reporting by GBHackers.
