Confucius Pakistan phishing campaign using WooperStealer and Anondoor
Campaign
Summary
Hide ▲
Show ▼
Confucius is running an active phishing campaign against Pakistan that uses WooperStealer and Anondoor, expanding the risk of credential theft and device compromise across a broad target set. The operation has targeted government agencies, military organizations, defense contractors, and critical industries using spear-phishing and malicious documents. Recent attack chains used .PPSX and .LNK files with DLL side-loading to deliver malware and steal sensitive data. The group’s repeated targeting and changing toolset suggest a sustained operation rather than a single isolated lure.
Related Happenings
Silver Fox South Asia phishing campaign
Campaign
H score34
First: 24.03.2026 18:00
Last: 24.03.2026 18:00
Sources 1
About this happening:
The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Fox South Asia phishing campaign
CampaignAbout this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...
Silver Dragon intrusion and phishing campaign targeting Europe, Southeast Asia, and Uzbekistan
Campaign
H score36
First: 04.03.2026 10:14
Last: 04.03.2026 10:14
Sources 1
About this happening:
The Silver Dragon campaign is actively using public-facing internet servers and phishing emails with malicious attachments to gain initial access, expanding risk acros...
Silver Dragon intrusion and phishing campaign targeting Europe, Southeast Asia, and Uzbekistan
CampaignAbout this happening: The Silver Dragon campaign is actively using public-facing internet servers and phishing emails with malicious attachments to gain initial access, expanding risk acros...
Mustang Panda multi-country espionage campaign against government and telecom targets
Campaign
H score37
First: 28.01.2026 13:40
Last: 28.01.2026 13:40
Sources 1
About this happening:
Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
Mustang Panda multi-country espionage campaign against government and telecom targets
CampaignAbout this happening: Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...
Storm-0249 tax-themed phishing campaign targeting U.S. users
Campaign
H score29
First: 09.12.2025 15:37
Last: 09.12.2025 15:37
Sources 1
About this happening:
Storm-0249 ran a tax-themed phishing campaign against U.S. users ahead of the tax filing season, expanding access opportunities for downstream abuse. The operation...
Storm-0249 tax-themed phishing campaign targeting U.S. users
CampaignAbout this happening: Storm-0249 ran a tax-themed phishing campaign against U.S. users ahead of the tax filing season, expanding access opportunities for downstream abuse. The operation...
STAC6565 spear-phishing campaign targeting Canadian organizations
Campaign
H score41
First: 09.12.2025 11:35
Last: 09.12.2025 11:35
Sources 1
About this happening:
The STAC6565 campaign has driven almost 40 intrusions against Canadian organizations, making it a sustained operation with a sharply focused target set. Attackers use...
STAC6565 spear-phishing campaign targeting Canadian organizations
CampaignAbout this happening: The STAC6565 campaign has driven almost 40 intrusions against Canadian organizations, making it a sustained operation with a sharply focused target set. Attackers use...
Timeline
-
02.10.2025 17:44 2 articles · 9mo ago
Confucius Pakistan phishing campaign using WooperStealer and Anondoor
Initial DisclosureThe earliest documented wave used a .PPSX lure in December 2024 to deliver WooperStealer through DLL side-loading. That phase established the campaign’s reliance on phishing documents as the entry point.
Show sources
- Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware — thehackernews.com — 02.10.2025 17:44
- Confucius Hackers Hit Pakistan With New WooperStealer and Anondoor Malware — thehackernews.com — 02.10.2025 17:44