Home/Threat Actor/Confucius (India-Aligned APT)
Threat Actor

Confucius (India-Aligned APT)

confucius · india_aligned_apt_active_2013_pakistan_china_south_asia_government_military_targeting · active since 2013-01

Confucius is an India-aligned APT active since at least 2013 targeting Pakistan + China + South Asia + East Asia government and military entities per capalearning 2025 coverage ("Confucius is believed to be a threat group with objectives aligned with India. It has been active since at least 2013, targeting government and military units in South Asia and East Asia") with 2025 WooperStealer information stealer + Anondoor previously-undocumented modular backdoor new custom malware disclosure ("Confucius has been associated with a new campaign deploying an information stealer called WooperStealer and a previously undocumented modular backdoor Anondoor") + tool-sharing operational overlaps with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder Indian-aligned cluster family per Proofpoint + Recorded Future / Insikt Group analysis ("tool-sharing overlaps with other suspected Indian threat actors, including Mysterious Elephant (also known as APT-K-47) and Confucius") + operational adjacency with Patchwork (already curated as patchwork.yaml in corpus) which is also India-aligned per industry consensus.

India-aligned attribution per 2025 industry consensus (Proofpoint + Recorded Future / Insikt Group + Seqrite Labs + The Record + capalearning + Threatray) based on tool-sharing pattern analysis with confirmed India-aligned clusters Bitter/TA397 + SideWinder + Mysterious Elephant grouped together as India-linked state- sponsored cyberespionage groups.

honest attribution caveat India-aligned consensus is 2025-emerged industry agreement + earlier reporting variously characterized Confucius (some Pakistan-aligned attribution exists in older literature), current 2025 industry consensus supports India-aligned attribution based on tool-sharing patterns.

standalone cluster paralleling unc1860 + unc4990 + teamtnt in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

operational target profile signature South Asia + East Asia government + military targeting per capalearning + signature Pakistan + China primary targets consistent with Indian state intelligence priorities + signature diplomatic + government victimology consistent with state-aligned regional espionage objectives.

operational attack architecture: (1) cluster-defining 2013+ long-running operational history with 12+ year continuous operations establishing cluster as one of longest-running South Asian regional APTs.

(2) cluster-defining India- aligned attribution 2025 industry consensus via Proofpoint + Recorded Future / Insikt Group + Seqrite + The Record + capalearning + Threatray tool-sharing pattern analysis with confirmed India-aligned clusters.

(3) cluster-defining Pakistan + China + South Asia + East Asia government + military targeting signature reflecting Indian state intelligence priorities with regional cyberespionage focus.

(4) cluster- defining 2025 WooperStealer information stealer + Anondoor modular backdoor new custom malware disclosure signature per capalearning July 2025 establishing 2025 tradecraft expansion with new tooling beyond traditional document-exploit delivery.

(5) cluster-defining tool-sharing Indian-aligned cluster family operational overlap signature with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder + operational adjacency with Patchwork (already curated) + Transparent Tribe/APT36/mythic_leopard (Pakistan- aligned reverse-target relationship)

(6) signature spearphishing with malicious attachments tradecraft + VBA macros + document exploitation historic pattern + evolution to information stealer + modular backdoor sophistication in 2025; (7) signature operational continuity through 2013-2025 period with sustained South Asian regional espionage focus.

(8) signature Indian regional intelligence priorities reflection in target selection (Pakistan + China principal adversaries)

(9) signature industry-consensus attribution-shift from older varied Pakistan/ India-aligned literature to 2025 India-aligned consensus based on tool-sharing-pattern analysis methodology; cluster fills the India-aligned-APT-active-2013 + Pakistan-China-South-Asia-government-military- targeting + WooperStealer-information-stealer- Anondoor-modular-backdoor-2025-disclosure + tool-sharing-Bitter-TA397-Mysterious-Elephant- APT-K-47-SideWinder-Indian-aligned-cluster- family + 2025-Proofpoint-Recorded-Future-Seqrite- capalearning-India-aligned-industry-consensus + Patchwork-operational-adjacency + 12-year-long- running-operational-history position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

canonical illustration of India-aligned APT methodology + Pakistan + China South Asian regional cyberespionage focus + long-running 12+ year operational history + WooperStealer + Anondoor 2025 custom malware family + tool-sharing Indian-aligned cluster family operational overlap with Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder cited in essentially all subsequent India-aligned-APT industry analyses through 2013-2026 period.

india_aligned_apt_active_2013_pakistan_china_south_asia_government_military_targeting confidence: high 16 aliases MITRE ATT&CK G0142 ↗
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Confucius is an India-aligned APT active since at least 2013 targeting Pakistan + China + South Asia government and military entities, with 2025 WooperStealer information stealer + Anondoor modular backdoor new custom malware disclosure + tool-sharing operational overlaps with Bitter/ TA397 + Mysterious Elephant/APT-K-47 + SideWinder Indian-aligned cluster family + operational adjacency with Patchwork (already curated). India-aligned attribution per 2025 industry consensus (Proofpoint + Recorded Future / Insikt Group + Seqrite + The Record + capalearning) based on tool-sharing pattern analysis with confirmed India-aligned clusters. Honest attribution caveat: India-aligned consensus is 2025-emerged, earlier reporting variously characterized Confucius (some Pakistan-aligned attribution exists in older literature).

Current 2025 industry consensus supports India-aligned attribution. Standalone cluster paralleling unc1860 + unc4990 + teamtnt in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

Operational target profile
  • Pakistan primary.
  • China primary.
  • South Asia + East Asia government + military signature Operational attack architecture: (1) India-aligned APT active since 2013 (cluster-defining) (2) Pakistan + China + South Asia government + military targeting (cluster-defining) (3) 2025 WooperStealer information stealer + Anondoor modular backdoor (cluster-defining) (4) Tool-sharing Indian-aligned cluster family operational overlap (Bitter/TA397 + Mysterious Elephant/APT-K-47 + SideWinder + Patchwork) (cluster-defining) (5) 12+ year long-running operational history (cluster-defining) (6) 2025 industry consensus India-aligned attribution shift (cluster-defining) The cluster fills the India-aligned-APT-active- 2013 + Pakistan-China-South-Asia-government- military-targeting + WooperStealer-information- stealer-Anondoor-modular-backdoor-2025-disclosure + tool-sharing-Bitter-TA397-Mysterious-Elephant- APT-K-47-SideWinder-Indian-aligned-cluster- family + 2025-Proofpoint-Recorded-Future-Seqrite- capalearning-India-aligned-industry-consensus + Patchwork-operational-adjacency position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.

Aliases

16
confuciusconfucius aptconfucius_aptconfucius threat groupconfucius india-aligned aptconfucius pakistan china south asia targetingconfucius 2013 active sinceconfucius wooperstealer information stealer 2025confucius anondoor modular backdoor 2025confucius bitter ta397 tool-sharing overlapconfucius mysterious elephant apt-k-47 tool-sharing overlapconfucius sidewinder indian-aligned cluster familyconfucius traditional south asian regional espionage focusconfucius government military targeting south asia east asiaconfucius indian state-aligned objectives proofpoint recorded future seqriteconfucius patchwork operational adjacency

Notable Campaigns

7
2025Confucius India-Aligned Attribution 2025 Industry Consensus Signature
2025Confucius 2025 WooperStealer + Anondoor New Custom Malware Disclosure Signature
2024-2025Confucius Tool-Sharing Indian-Aligned Cluster Family Operational Overlap Signature
2013-2026Continued Industry Reference Status (2013-2026)
2013-2025Confucius South Asia + East Asia Government + Military Targeting Signature
2013-2025Confucius Patchwork Operational Adjacency Signature (Both India-Aligned)
2013Confucius Origin, 2013 Long-Running South Asia + East Asia Espionage

Attribution & Reporting

Attributed by
Proofpoint (canonical 2025 India-aligned tool-sharing overlap analysis)Recorded Future / Insikt Group (canonical 2025 South Asian hackers + Mysterious Elephant + Indian-aligned cluster family analysis)Seqrite Labs (canonical Indian government Pakistani APT analysis providing reverse-perspective)The Record / Recorded Future News (canonical 2025 India-aligned cluster coverage)capalearning (canonical 2025 Confucius WooperStealer + Anondoor + India-aligned coverage)Threatray (canonical Bitter/TA397 + Confucius tool-sharing analysis)
Key reporting
reportProofpoint (2025): canonical Bitter/TA397 + Confucius tool-sharing overlap analysis
reportRecorded Future / Insikt Group (2025): canonical Mysterious Elephant + Indian-aligned cluster family analysis
reportSeqrite Labs (2024-2025): canonical Indian government Pakistani APT analysis (reverse-perspective)
reportThe Record / Recorded Future News: India-aligned cluster family coverage
reportcapalearning (July 2025): Confucius WooperStealer + Anondoor + India-aligned coverage
reportThreatray (2025): Bitter/TA397 + Confucius tool-sharing analysis

Operational

State sponsor

Confucius is an India-aligned APT active since at least 2013 targeting Pakistan + China + South Asia government and military entities. Per capalearning via 2025 industry coverage: "Confucius is believed to be a threat group with objectives aligned with India. It has been active since at least 2013, targeting government and military units in South Asia and East Asia." Per Proofpoint via The Record (June 2025): "tool- sharing overlaps with other suspected Indian threat actors, including Mysterious Elephant (also known as APT-K-47) and Confucius." Per The Record / Recorded Future (June 2025): "The group's [Mysterious Elephant/APT-K-47] goals and techniques are similar to those used by India-linked state-sponsored cyberespionage groups, including SideWinder, Confucius and Bitter." Honest attribution caveat: India-aligned consensus is 2025-emerged industry agreement.

Earlier reporting variously characterized Confucius as Pakistan-aligned in some sources + India-aligned in others, current 2025 industry consensus (Proofpoint + Recorded Future / Insikt Group + Seqrite + capalearning) supports India- aligned attribution based on tool-sharing patterns with confirmed-India-aligned clusters Bitter/TA397 + SideWinder + Mysterious Elephant. Confucius shares operational adjacency with Patchwork (already curated as patchwork.yaml) which is also India-aligned per industry consensus. Attribution chain: (1) 2013+ long-running operational history: per capalearning via Recorded Future / Insikt Group + 2025 industry consensus: Confucius active since at least 2013 with continuous operations targeting South Asian + East Asian government and military entities establishing cluster-defining 12+ year operational history.

(2) India-aligned 2025 industry consensus: per Proofpoint + Recorded Future / Insikt Group + Seqrite + The Record + capalearning: 2025 industry coverage establishes Confucius as India-aligned APT through tool-sharing pattern analysis with confirmed India-aligned clusters. (3) Indian-aligned cluster family operational overlap signature: per The Record / Recorded Future: "The researchers also noted tool-sharing overlaps with other suspected Indian threat actors, including Mysterious Elephant (also known as APT-K-47) and Confucius." Per capalearning: SideWinder + Bitter + Confucius + Mysterious Elephant grouped as India-linked state-sponsored cyberespionage groups. (4) 2025 WooperStealer + Anondoor new malware disclosure: per capalearning July 2025: "As the cyber espionage actor known as Confucius has been associated with a new campaign deploying an information stealer called WooperStealer and a previously undocumented modular backdoor Anondoor." Cluster-defining 2025 tradecraft expansion signature.

(5) South Asia + East Asia government + military targeting signature: per capalearning: "targeting government and military units in South Asia and East Asia" with Pakistan + China + regional focus consistent with Indian state intelligence priorities.

Operational target profile
  • South Asia government signature primary per capalearning.
  • South Asia military signature primary.
  • East Asia government + military signature.
  • Pakistan primary target consistent with Indian regional intelligence priorities.
  • China target consistent with Indian regional intelligence priorities The cluster fills the India-aligned-APT-active- 2013 + Pakistan-China-South-Asia-government- military-targeting + WooperStealer-information- stealer-Anondoor-modular-backdoor-2025-disclosure + tool-sharing-Bitter-TA397-Mysterious-Elephant- APT-K-47-SideWinder-Indian-aligned-cluster- family + 2025-Proofpoint-Recorded-Future-Seqrite- capalearning-India-aligned-industry-consensus + Patchwork-operational-adjacency position in v0.1.178 heterogeneous nation-state + criminal cluster gap-filler cell.
Motivations
india_aligned_apt_state_aligned_objectives, pakistan_china_south_asia_government_military_targeting, wooperstealer_anondoor_2025_custom_malware_signature, tool_sharing_indian_aligned_cluster_family_overlap, 12_year_long_running_operational_history_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SOUTH ASIA + EAST ASIA GOVERNMENT + MILITARY TARGETING SIGNATURESPEARPHISHING WITH MALICIOUS ATTACHMENTS TRADECRAFT
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin