CONFUCIUS_B is a Windows backdoor family associated with politically motivated intrusion activity and loosely linked through infrastructure and tradecraft to Patchwork and Hangover-related operations. It has also been assessed as likely sharing development lineage with the related CONFUCIUS_A cluster because both families use an uncommon command-and-control discovery technique that hides resolver traffic inside requests to legitimate web services rather than relying on direct DNS lookups.
A defining characteristic of CONFUCIUS_B is its use of public web content as an intermediary for command-and-control resolution. The malware beacons to legitimate services including Quora and Yahoo Answers, extracts selected keywords from retrieved content, and maps those words through an internal lookup table to reconstruct an IP address for subsequent command-and-control communication. This approach helps initial network activity blend with normal browsing traffic. CONFUCIUS_B implements this resolver differently from CONFUCIUS_A, using its own custom obfuscation scheme and an embedded packed executable that performs the decoding logic.
Observed delivery includes a self-extracting archive disguised as a presentation file through filename spoofing and decoy content. In one documented execution chain, the dropper wrote multiple files to the user profile area, used script components to launch a batch file, displayed a decoy presentation, and then executed a second-stage payload. CONFUCIUS_B has also been observed as the final payload in exploit chains abusing the InPage word processor, where politically themed lure documents related to India, Kashmir, and terrorism delivered staged malware culminating in the CONFUCIUS_B backdoor.
The family exhibits typical backdoor behavior, including staged execution, command-and-control beaconing, and obfuscation intended to hinder analysis. Available reporting supports its role as a post-compromise remote access payload, but detailed public documentation of its full command set is limited in the supplied facts. Targeting context and lure themes indicate use in espionage-oriented campaigns, particularly in South Asian geopolitical contexts.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In doing so, we encountered another set of samples exhibiting very similar behavior, which we refer to as CONFUCIUS_B, due to their similarity, and their likely similar origins.
23 distinct techniques documented for this family, organized by ATT&CK tactic.
The decoy documents used by the InPage exploits suggest that the targets are likely to be politically or militarily motivated. They contained subjects such as intelligence reports and political situations related to India, the Kashmir region, or terrorism being used as lure documents.
Fancy.vbs executes fancy.bat, which in turn opens the presentation and runs the second stage executable svchost.exe.
Fancy.vbs executes fancy.bat, which in turn opens the presentation and runs the second stage executable svchost.exe.
This particular shellcode uses a unique hashing mechanism for identifying and loading Microsoft Windows libraries and functions.
Svchost.exe has a custom obfuscation scheme not seen in CONFUCIUS_A... Underneath that custom obfuscation lies a UPX packed executable
Underneath that custom obfuscation lies a UPX packed executable...
The CONFUCIUS_B executable is disguised as a PowerPoint presentation, using a Right-To-Left-Override (RTLO) trick and a false icon.
The CONFUCIUS_B executable is disguised as a PowerPoint presentation, using a Right-To-Left-Override (RTLO) trick and a false icon.
Finally, the malware will spawn a new suspended instance of itself, where the decrypted data is written and subsequently executed.
It proceeds to decrypt an embedded resource object using the RC4 algorithm.
This particular executable is made to resemble the legitimate application Putty.
All of the CONFUCIUS_B samples share the same mutex, “rCkBs1Uj493NaMXYY1LZ”.
both using Yahoo Answers and Quora to evade traditional mechanisms for blocking command and control domains
The malware requests the page shown below in order to determine what IP to POST to... Figure 4 – HTTP POST request made to command and control server
the same domain hosted the sample 8cfd559756630d967bb597b087af98adc75895a1ec52586d53a2d898e4a6e9b0... a known command and control address for CONFUCIUS_B.
cyber espionage threat actors are increasingly abusing legitimate web services, in lieu of DNS lookups to retrieve a command and control address... more recent samples of the CONFUCIUS_A malware use a range of legitimate web services to resolve command and control addresses, the highest profile of which are Yahoo and Quora.
142 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor payload delivered via malicious InPage exploit documents. In the described chain, it is the final stage after multiple droppers and loaders and is used for C2 operations.
A final-stage backdoor payload dropped by one of the malicious InPage exploit chains and used for C2 operations.
Final-stage backdoor payload dropped by an InPage exploit chain; used for C2 operations.
Backdoor malware family similar to CONFUCIUS_A that is delivered in SFX RAR packages and uses scripts plus a second-stage executable. It contacts Yahoo and Quora, extracts keywords from pages, maps them through an in-memory lookup table, and derives an IP address for subsequent C2 communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.