Palo Alto Networks detailed two related malware families, CONFUCIUS_A and CONFUCIUS_B, that concealed command-and-control discovery inside traffic to legitimate web services including Quora and Yahoo Answers. Instead of performing direct DNS lookups, the malware parsed words embedded in public web content and translated them into IP addresses through lookup tables, allowing early-stage beaconing to blend into normal browsing activity. Researchers said the uncommon resolver technique and code similarities point to a shared developer or development shop, even though the campaigns were likely operated separately.
CONFUCIUS_A was linked through overlapping infrastructure to SNEEPY/ByeByeShell activity and was observed primarily targeting organizations in Pakistan, the Middle East, and parts of Asia, with some broader enterprise victims also seen. CONFUCIUS_B used a similar concept with a different implementation, including delivery through a self-extracting RAR archive disguised with RTLO as a PowerPoint file, followed by scripts and a second-stage executable; it also showed looser ties to Patchwork/Hangover through shared infrastructure, mutexes, and certificate relationships.

Get the actors, campaigns, and ATT&CK mapping behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On this date, the domain com-account-jfnjkr.xyz hosted a basic file stealer associated with Patchwork via the shared mutex {9754893678976458374658764387563876}. The same domain was also used as command-and-control infrastructure for a sample that downloaded CONFUCIUS_B, creating a loose link between the clusters.
The attackers behind CONFUCIUS_A were observed dropping the backdoor starting in early 2014. The malware was commonly delivered via executable files sent directly to targets by email.
Rapid7 first reported attacks associated with the SNEEPY, or ByeByeShell, backdoor method against Pakistani targets. Later analysis linked CONFUCIUS_A to this earlier activity through overlapping infrastructure.
Unit 42 published research on the related malware families CONFUCIUS_A and CONFUCIUS_B, describing how they abused Yahoo Answers and Quora to derive command-and-control addresses from legitimate web traffic. The report assessed that the unusual shared technique suggested a common developer or development shop, though likely different operators used the two clusters.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 166 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
researchcenter.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.