Threat actor · all actors
ConfuciusG0142 unknown
aka Confucius, Confucius APT
Last updated: 2026-08-20
About this actor
[Confucius](https://attack.mitre.org/groups/G0142) is a cyber espionage group that has primarily targeted military personnel, high-profile personalities, business persons, and government organizations in South Asia since at least 2013. Security researchers have noted similarities between [Confucius](https://attack.mitre.org/groups/G0142) and [Patchwork](https://attack.mitre.org/groups/G0040), particularly in their respective custom malware code and targets.(Citation: TrendMicro Confucius APT Feb 2018)(Citation: TrendMicro Confucius APT Aug 2021)(Citation: Uptycs Confucius APT Jan 2021)
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 28 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
T1041Exfiltration Over C2 Channel ↗T1053Scheduled Task/Job ↗T1053.005Scheduled Task ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.005Visual Basic ↗T1071Application Layer Protocol ↗T1071.001Web Protocols ↗T1083File and Directory Discovery ↗T1105Ingress Tool Transfer ↗T1119Automated Collection ↗T1203Exploitation for Client Execution ↗T1204User Execution ↗T1204.001Malicious Link ↗T1204.002Malicious File ↗T1218System Binary Proxy Execution ↗T1218.005Mshta ↗T1221Template Injection ↗T1547Boot or Logon Autostart Execution ↗T1547.001Registry Run Keys / Startup Folder ↗T1566Phishing ↗T1566.001Spearphishing Attachment ↗T1566.002Spearphishing Link ↗T1567Exfiltration Over Web Service ↗T1567.002Exfiltration to Cloud Storage ↗T1583Acquire Infrastructure ↗T1583.006Web Services ↗T1680Local Storage Discovery ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 21 / 28 | 75% |
CM-2 | 18 / 28 | 64% |
CM-6 | 18 / 28 | 64% |
SI-3 | 18 / 28 | 64% |
CA-7 | 16 / 28 | 57% |
SC-7 | 15 / 28 | 54% |
AC-4 | 14 / 28 | 50% |
CM-7 | 13 / 28 | 46% |
CM-8 | 10 / 28 | 36% |
SI-7 | 10 / 28 | 36% |
AC-6 | 9 / 28 | 32% |
RA-5 | 9 / 28 | 32% |
SI-2 | 9 / 28 | 32% |
AC-2 | 8 / 28 | 29% |
AC-3 | 8 / 28 | 29% |
Co-occurring actors
None.
Similar actors
Similar TTPs
- LazyScripter 0.41
- Molerats 0.39
- Rancor 0.38
- Sidewinder 0.37
- Inception 0.35