Malware
Confucius
Indicators of Compromise 21
Domain bloomwpp[.]info Domain cms[.]balochistanpolice[.]gov[.]pk Domain cornfieldblue[.]info Domain dropmicis[.]info Domain greenxeonsr[.]info Domain hauntedfishtree[.]info Domain marshmellowflowerscar[.]info Domain martkartout[.]info Domain petricgreen[.]info Filename 360Safe.exe Filename cms_plugin.exe SHA-256 06b8f395fc6b4fda8d36482a4301a529c21c60c107cbe936e558aef9f56b84f6 SHA-256 11391799ae242609304ef71b0efb571f11ac412488ba69d6efc54557447d022f SHA-256 13ca36012dd66a7fa2f97d8a9577a7e71d8d41345ef65bf3d24ea5ebbb7c5ce1 SHA-256 24b06b5caad5b09729ccaffa5a43352afd2da2c29c3675b17cae975b7d2a1e62 SHA-256 4206ab93ac9781c8367d8675292193625573c2aaacf8feeaddd5b0cc9136d2d1 SHA-256 5a0dd2451a1661d12ab1e589124ff8ecd2c2ad55c8f35445ba9cf5e3215f977e SHA-256 8603b9fa8a6886861571fd8400d96a705eb6258821c6ebc679476d1b92dcd09e SHA-256 c91917ff2cc3b843cf9f65e5798cd2e668a93e09802daa50e55a842ba9e505de IP 142[.]171[.]183[.]8 IP 193[.]42[.]25[.]65
MITRE ATT&CK TTPs 11
T1027 T1048 T1053.005 T1055 T1059.001 T1071.001 T1074 T1082 T1085 T1114 T1204.002
Obfuscated Files or Information
Defense Evasion
Exfiltration Over Alternative Protocol
Exfiltration
Scheduled Task
Execution
Process Injection
Defense Evasion
PowerShell
Execution
Web Protocols
Command And Control
Data Staged
Collection
System Information Discovery
Discovery
T1085
Email Collection
Collection
Malicious File
Execution
Source Articles
Confucius Espionage: From Stealer to Backdoor | FortiGuard Labs
The Confucius threat group, a state-aligned cyber-espionage actor, has evolved its tactics from using document stealers like WooperStealer to deploying Python-based backdoors such as AnonDoor. Initially targeting organizations in Pakistan via spear-phishing and malicious Office documents, the group has advanced to using LNK files, DLL side-loading, and scheduled tasks for persistence. Their campaigns now feature layered obfuscation, custom Python RATs, and sophisticated data exfiltration techniques, indicating a growing level of operational sophistication.
fortinet
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Cyber espionage campaigns targeting Pakistani law enforcement agencies, including the Balochistan Police, have been conducted by suspected China- and India-aligned threat actors between February 2024 and April 2026. The attackers exploited web applications such as the Complaint Management System to deploy custom malware, including PlugX, ShadowPad, Cobalt Strike, and Remcos RAT. These operations targeted sensitive data including biometric records, criminal files, and personnel information, with infrastructure overlaps linking some activity to known threat groups like Mysterious Elephant. The compromise of public-facing portals extended the attack surface to both law enforcement and citizens.
hacker-news ·2w ago