Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware

Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware

Posted on October 2, 2025October 2, 2025 By CWS

Oct 02, 2025Ravie LakshmananMalware / Cyber Espionage
The risk actor often known as Confucius has been attributed to a brand new phishing marketing campaign that has focused Pakistan with malware households like WooperStealer and Anondoor.
“Over the previous decade, Confucius has repeatedly focused authorities businesses, navy organizations, protection contractors, and important industries — particularly in Pakistan – utilizing spear-phishing and malicious paperwork as preliminary entry vectors,” Fortinet FortiGuard Labs researcher Cara Lin mentioned.
Confucius is a long-running hacking group that is believed to have been energetic since 2013 and working throughout South Asia. Latest campaigns undertaken by the risk actor have employed a Python-based backdoor known as Anondoor, signaling an evolution of the group’s tradecraft and its technical agility.

One of many assault chains documented by Fortinet focused customers in Pakistan someday in December 2024, tricking recipients into opening a .PPSX file, which then triggers the supply of WooperStealer utilizing DLL side-loading strategies.
A subsequent assault wave noticed in March 2025 has been discovered to make use of Home windows shortcut (.LNK) recordsdata to unleash the malicious WooperStealer DLL, once more launched utilizing DLL side-loading, to steal delicate information from compromised hosts.
One other .LNK file noticed in August 2025 additionally leveraged related techniques to sideload a rogue DLL, solely this time the DLL paves the way in which for Anondoor, a Python implant that is designed to exfiltrate gadget data to an exterior server and await additional duties to execute instructions, take screenshots, enumerate recordsdata and directories, and dump passwords from Google Chrome.

It is value noting that the risk actor’s use of Anondoor was documented in July 2025 by Seebug’s KnownSec 404 Workforce.
“The group has demonstrated robust adaptability, layering obfuscation strategies to evade detection and tailoring its toolset to align with shifting intelligence-gathering priorities,” Fortinet mentioned. “Its current campaigns not solely illustrate Confucius’ persistence but additionally its skill to pivot quickly between strategies, infrastructure, and malware households to keep up operational effectiveness.”

The disclosure comes as K7 Safety Labs detailed an an infection sequence related to the Patchwork group that commences with a malicious macro that is designed to obtain a .LNK file containing PowerShell code chargeable for downloading extra payloads and leveraging DLL side-loading to launch the first malware whereas concurrently displaying a decoy PDF doc.
The ultimate payload, for its half, establishes contact with the risk actor’s command-and-control (C2) server, gathers system data, and retrieves an encoded instruction that is subsequently decrypted for execution utilizing cmd.exe. It is also geared up to take screenshots, add recordsdata from the machine, and obtain recordsdata from a distant URL and save them domestically in a brief listing.
“The malware waits for a configurable interval and retries sending the info as much as 20 occasions, monitoring failures to make sure persistent and stealthy information exfiltration with out alerting the person or safety methods,” the corporate mentioned.

The Hacker News Tags:Anondoor, Confucius, Hackers, Hit, Malware, Pakistan, WooperStealer

Post navigation

Previous Post: New Obex Tool Blocks EDR Dynamic Libraries From Loading at Runtime
Next Post: Top 10 Best End-to-End Threat Intelligence Compaines in 2025

Related Posts

3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 3 Decisions CISOs Need to Make to Prevent Downtime Risk in 2026 The Hacker News
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain Risks The Hacker News
Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper Malicious npm Package Leverages Unicode Steganography, Google Calendar as C2 Dropper The Hacker News
Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts Record 29.7 Tbps DDoS Attack Linked to AISURU Botnet with up to 4 Million Infected Hosts The Hacker News
WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately The Hacker News
Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution
  • Unpatched BitLocker Flaws Expose Windows Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution
  • Critical 18-Year NGINX Vulnerability Enables Remote Code Execution
  • Unpatched BitLocker Flaws Expose Windows Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark