Illustration depicting the Confucius threat group targeting Pakistan with WooperStealer and Anondoor malware through spear-phishing and DLL side-loading attacks.

Confucius Hackers Target Pakistan with WooperStealer and Anondoor Malware

Cybersecurity researchers have uncovered a new phishing campaign attributed to the Confucius threat group that targets organizations in Pakistan using two malware families, WooperStealer and Anondoor.

According to Fortinet FortiGuard Labs, Confucius has consistently focused on government agencies, military organizations, defense contractors, and other critical sectors across South Asia for more than a decade, with Pakistan remaining one of its primary targets. The group commonly relies on spear-phishing emails and malicious document attachments to gain initial access to victim systems.

Believed to have been active since 2013, Confucius is a long-running cyber espionage group operating throughout South Asia. Researchers note that its more recent operations have introduced Anondoor, a Python-based backdoor that reflects the group’s continued evolution in malware development and attack techniques.

Fortinet identified one attack campaign that targeted users in Pakistan during December 2024. In that operation, victims were lured into opening a malicious .PPSX presentation file, which ultimately delivered WooperStealer through a DLL side-loading technique.

A second wave of attacks observed in March 2025 adopted a different delivery method by using malicious Windows shortcut (.LNK) files. Once executed, these files deployed the WooperStealer DLL through DLL side-loading, enabling attackers to collect sensitive information from compromised systems.

Researchers also discovered another malicious LNK-based campaign in August 2025. While the infection method remained largely unchanged, the payload shifted from WooperStealer to Anondoor. The Python-based backdoor is designed to transmit system information to a remote server before waiting for additional instructions. It can execute commands, capture screenshots, browse files and directories, and extract saved passwords from Google Chrome.

The use of Anondoor by Confucius was previously documented in July 2025 by KnownSec 404 Team (Seebug). Researchers believe the group’s transition from deploying information stealers to using a full-featured backdoor indicates a strategic move toward long-term persistence, continuous surveillance, and broader espionage capabilities.

According to Fortinet, the threat actor continues to refine its operations by combining multiple obfuscation methods to avoid detection while regularly updating its malware toolkit to match changing intelligence objectives. The latest campaigns demonstrate Confucius’ ability to quickly adapt its techniques, infrastructure, and malware families to sustain operational effectiveness.

Government organizations across South Asia continue to face sustained cyber espionage campaigns from multiple threat groups. In a separate operation, researchers recently linked the Pakistan-based SideCopy group to attacks targeting Afghanistan’s Ministry of Finance with the Xeno RAT malware. Read our full report on the SideCopy campaign targeting Afghanistan’s Ministry of Finance with Xeno RAT

The findings were disclosed alongside a separate report from K7 Security Labs, which analyzed an attack chain associated with the Patchwork threat group. In that campaign, attackers used a malicious Microsoft Office macro to download a Windows .LNK file containing PowerShell commands that retrieved additional payloads. The malware was then launched through DLL side-loading, while a decoy PDF document was displayed to reduce suspicion.

The final payload communicates with a command-and-control (C2) server, collects system information, and downloads encrypted instructions that are decrypted and executed through cmd.exe. It also supports screenshot capture, file uploads, and downloading files from remote URLs before storing them in a temporary directory.

K7 Security Labs added that the malware includes a configurable retry mechanism, allowing it to pause for a specified interval and attempt data transmission up to 20 times. This approach helps maintain reliable and stealthy data exfiltration while minimizing the chances of alerting users or security solutions.

Leave a Comment

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *