The advanced persistent threat (APT) group known as Confucius has intensified its cyber-espionage operations against Pakistani targets by evolving its malware arsenal and attack techniques. Confucius, active since 2013 and believed to be linked to India-sponsored cyber operations, has historically targeted government agencies, military organizations, defense contractors, and critical industries in Pakistan. Recent research by FortiGuard Labs reveals a significant shift in the group’s tactics, moving from the use of infostealers to more sophisticated Python-based backdoors. The group’s latest campaigns have leveraged spear-phishing emails and malicious documents as initial access vectors, a hallmark of their operations over the past decade. In December 2024, Confucius used a phishing campaign that delivered WooperStealer via a malicious .PPSX file, utilizing DLL side-loading techniques to compromise Windows-based systems. This was followed by another wave in March 2025, where Windows shortcut (.LNK) files were used to sideload the WooperStealer DLL, enabling the theft of sensitive data from infected hosts. By August 2025, the group had further refined its approach, using .LNK files to sideload a rogue DLL that deployed Anondoor, a Python-based implant. Anondoor is capable of exfiltrating device information, executing commands, taking screenshots, enumerating files and directories, and dumping passwords from Google Chrome, providing the attackers with persistent surveillance capabilities. The use of Anondoor was first documented by Seebug's KnownSec 404 Team in July 2025, highlighting the group’s ongoing innovation. Confucius has demonstrated strong adaptability by layering obfuscation techniques to evade detection and tailoring its toolset to shifting intelligence-gathering priorities. The group’s campaigns illustrate a clear evolution from short-term data theft to long-term monitoring and persistence within targeted networks. Researchers warn that this shift represents a significant increase in the group’s technical sophistication and operational objectives. The attacks underscore the persistent threat posed by state-sponsored actors in the South Asian region, particularly as they continue to refine their methods to bypass security controls. The campaigns have primarily targeted Microsoft Windows environments, exploiting common user behaviors such as opening email attachments and shortcut files. The group’s ability to rapidly adapt its malware and delivery mechanisms poses ongoing challenges for defenders. Security experts recommend heightened vigilance, user education, and robust endpoint protection to mitigate the risks associated with such advanced threats. The continued targeting of critical sectors in Pakistan by Confucius highlights the geopolitical motivations driving these cyber-espionage activities. Organizations in the region are urged to monitor for indicators of compromise related to WooperStealer and Anondoor and to implement layered security measures to detect and respond to such threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
On October 2, 2025, FortiGuard Labs publicly disclosed that Confucius had evolved from using WooperStealer to deploying the more capable AnonDoor backdoor in Pakistan-focused espionage operations. The report highlighted the group's adaptability, obfuscation changes, and released indicators of compromise to help defenders detect related activity.
Analysis of the August 2025 AnonDoor variant showed it could fingerprint hosts, execute commands, capture screenshots, enumerate and exfiltrate files, and steal Chrome passwords, with one version resembling an MSIL-based implant. Researchers also noted a distinctive data-formatting scheme before exfiltration and command-and-control infrastructure that appeared geographically restricted, including to Pakistan.
In August 2025, Fortinet observed a notable escalation in which Confucius replaced its prior infostealer-focused approach with the Python-based backdoor AnonDoor on Windows targets in Pakistan. The intrusion used PowerShell to install Scoop, prepared the environment for Python execution, and established persistence with a scheduled task running pythonw.exe and a downloaded .pyc file.
Over the course of the observed campaigns, Confucius changed its delivery tactics from PowerPoint lure documents to phishing emails carrying LNK attachments disguised as files such as PDFs. The group continued to rely on DLL sideloading, including abuse of a renamed fixmapi.exe, to execute malicious payloads.
Fortinet reported that Confucius was still deploying the WooperStealer infostealer in campaigns seen as recently as March 2025. The activity continued to target Pakistani government, military, defense, and critical-sector entities.
Fortinet observed Confucius launching phishing campaigns targeting organizations in Pakistan beginning in December 2024. Early waves used lure documents such as PowerPoint files and delivered the WooperStealer infostealer through multi-stage chains involving scripts, LNK files, PowerShell, and DLL sideloading.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.