AnonDoor is a Python-based backdoor associated with the Confucius espionage group. Reporting describes it as a newer, more advanced payload used by Confucius as the group shifted from deploying the WooperStealer infostealer toward longer-term monitoring, persistence, and modular post-compromise capability. Confucius has been reported active since at least 2013 and primarily targets government agencies, military organizations, defense contractors, and other critical industries in South Asia, especially Pakistan; other reporting also places its targeting across South Asia and East Asia.
Observed delivery chains used phishing lures with malicious LNK attachments disguised as documents, including PDF-themed filenames such as NLC.pdf.lnk. In the August 2025 activity, the LNK downloaded a malicious DLL named python313.dll together with a legitimate Python executable renamed BlueAle.exe, which side-loaded the DLL. Related reporting states the chain also used PowerShell to install Scoop, configure a Python runtime, and download a hidden Python bytecode payload, winresume.pyc, into %LOCALAPPDATA%. Persistence was established via a scheduled task: Fortinet reported NetPolicyUpdate running pythonw.exe with winresume.pyc every 5 minutes, while Knownsec reported persistence embedded in AnonDoor itself via a scheduled task named SystemCheck writing BlueAle.exe.
AnonDoor performs host fingerprinting and system reconnaissance. Reported capabilities include collecting OS version, local IP address, host name, public IP address, IP geolocation, disk letters and disk sizes, and generating a host UUID from firmware and system attributes; other reporting notes use of wmic csproduct get uuid and public IP/geolocation services including api.ipify.org, ipinfo.io/ip, icanhazip.com, ifconfig.me/ip, ip-api.com, and ipwhois.app. One report states it concatenates collected data using the delimiters "uhhg" and "$!!$" before sending it to C2.
The malware supports interactive backdoor tasking from C2. High-confidence reported commands and functions include command execution, screenshot capture, file and directory listing, file download, folder download, basic host information collection, and password dumping. Fortinet specifically reported PasswordDumper functionality that retrieves additional Python tooling to steal credentials from Mozilla Firefox and Microsoft Edge; another report described browser password dumping for Firefox and Edge, while separate reporting also claimed Chrome password dumping. Knownsec described a modular architecture in which AnonDoor requests component download information from the server, downloads additional modules, and loads them dynamically for execution via an exported method named Yretisdkjhsfkjfh. Knownsec stated the analyzed sample downloaded WooperStealer as a component and that component C2 addresses were passed at runtime rather than embedded in the modules.
Analysts assessed that AnonDoor’s modular design, DLL side-loading, invoke-based loading, runtime parameterization of C2, and use of Python/C# components improve evasion, complicate sandbox analysis, conceal infrastructure, and hinder attribution and defense. Reported infrastructure and indicators tied to AnonDoor campaigns include bloomwpp.info, dropmicis.info, martkartout.info, the hidden payload name winresume.pyc, the DLL name python313.dll, the renamed loader BlueAle.exe, and the SHA-256 hash abefd29c85d69f35f3cf8f5e6a2be76834416cc43d87d1f6643470b359ed4b1b.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
For the convenience of subsequent description, it is named “anondoor” using the special string “anon” in the code.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
the UUID acquires the system firmware information (ACPI table), attempts to extract the first 16 bytes and return them, then concatenates them with the host name and user name
Obtain the host system version, local IP, host name, public IP and IP location... After obtaining the disk letter and size, send it to the server | the UUID acquires the system firmware information (ACPI table), attempts to extract the first 16 bytes and return them
The communication addresses of all components are passed through the anondoor parameter... by using the parameterized C2 (Command and Control) communication mechanism
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Python-based backdoor used in campaigns targeting multiple Southeast Asian countries.
Advanced Python backdoor (as described in the title).
Python-based backdoor deployed via LNK attachment and staged DLL sideloading, then persistence via scheduled task executing pythonw.exe with a downloaded .pyc. Capabilities include host fingerprinting/geolocation, drive enumeration, command execution, screenshot capture, file download/exfiltration, and fetching additional Python tools for browser credential theft (Firefox/Edge).
Python-based backdoor used in a Confucius APT campaign targeting Pakistan (delivered via spear-phishing per the content).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.