Confucius (India-Aligned APT)
Confucius is an India-aligned APT active since at least 2013 targeting Pakistan + China + South Asia + East Asia government and military entities per capalearning 2025 coverage ("Confucius is believed to be a threat group with objectives aligned with India. It has been active since at least 2013, targeting government and military units in South Asia and East Asia") with 2025 WooperStealer information stealer + Anondoor previously-undocumented modular backdoor new custom malware disclosure ("Confucius has been associated with a new campaign deploying an information stealer called WooperStealer and a previously undocumented modular backdoor Anondoor") + tool-sharing operational overlaps with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder Indian-aligned cluster family per Proofpoint + Recorded Future / Insikt Group analysis ("tool-sharing overlaps with other suspected Indian threat actors, including Mysterious Elephant (also known as APT-K-47) and Confucius") + operational adjacency with Patchwork (already curated as patchwork.yaml in corpus) which is also India-aligned per industry consensus.
India-aligned attribution per 2025 industry consensus (Proofpoint + Recorded Future / Insikt Group + Seqrite Labs + The Record + capalearning + Threatray) based on tool-sharing pattern analysis with confirmed India-aligned clusters Bitter/TA397 + SideWinder + Mysterious Elephant grouped together as India-linked state- sponsored cyberespionage groups.
honest attribution caveat India-aligned consensus is 2025-emerged industry agreement + earlier reporting variously characterized Confucius (some Pakistan-aligned attribution exists in older literature), current 2025 industry consensus supports India-aligned attribution based on tool-sharing patterns.
standalone cluster paralleling unc1860 + unc4990 + teamtnt in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
operational target profile signature South Asia + East Asia government + military targeting per capalearning + signature Pakistan + China primary targets consistent with Indian state intelligence priorities + signature diplomatic + government victimology consistent with state-aligned regional espionage objectives.
operational attack architecture: (1) cluster-defining 2013+ long-running operational history with 12+ year continuous operations establishing cluster as one of longest-running South Asian regional APTs.
(2) cluster-defining India- aligned attribution 2025 industry consensus via Proofpoint + Recorded Future / Insikt Group + Seqrite + The Record + capalearning + Threatray tool-sharing pattern analysis with confirmed India-aligned clusters.
(3) cluster-defining Pakistan + China + South Asia + East Asia government + military targeting signature reflecting Indian state intelligence priorities with regional cyberespionage focus.
(4) cluster- defining 2025 WooperStealer information stealer + Anondoor modular backdoor new custom malware disclosure signature per capalearning July 2025 establishing 2025 tradecraft expansion with new tooling beyond traditional document-exploit delivery.
(5) cluster-defining tool-sharing Indian-aligned cluster family operational overlap signature with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder + operational adjacency with Patchwork (already curated) + Transparent Tribe/APT36/mythic_leopard (Pakistan- aligned reverse-target relationship)
(6) signature spearphishing with malicious attachments tradecraft + VBA macros + document exploitation historic pattern + evolution to information stealer + modular backdoor sophistication in 2025; (7) signature operational continuity through 2013-2025 period with sustained South Asian regional espionage focus.
(8) signature Indian regional intelligence priorities reflection in target selection (Pakistan + China principal adversaries)
(9) signature industry-consensus attribution-shift from older varied Pakistan/ India-aligned literature to 2025 India-aligned consensus based on tool-sharing-pattern analysis methodology; cluster fills the India-aligned-APT-active-2013 + Pakistan-China-South-Asia-government-military- targeting + WooperStealer-information-stealer- Anondoor-modular-backdoor-2025-disclosure + tool-sharing-Bitter-TA397-Mysterious-Elephant- APT-K-47-SideWinder-Indian-aligned-cluster- family + 2025-Proofpoint-Recorded-Future-Seqrite- capalearning-India-aligned-industry-consensus + Patchwork-operational-adjacency + 12-year-long- running-operational-history position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
canonical illustration of India-aligned APT methodology + Pakistan + China South Asian regional cyberespionage focus + long-running 12+ year operational history + WooperStealer + Anondoor 2025 custom malware family + tool-sharing Indian-aligned cluster family operational overlap with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder cited in essentially all subsequent India-aligned-APT industry analyses through 2013-2026 period.