Find notable cyber news and cases, enriched with sources, timelines, and signals.

Confucius Pakistan phishing campaign using WooperStealer and Anondoor

Campaign
First reported
Last updated
Happening score
H score 32
1 unique sources, 1 articles

Summary

Hide ▲

Confucius is running an active phishing campaign against Pakistan that uses WooperStealer and Anondoor, expanding the risk of credential theft and device compromise across a broad target set. The operation has targeted government agencies, military organizations, defense contractors, and critical industries using spear-phishing and malicious documents. Recent attack chains used .PPSX and .LNK files with DLL side-loading to deliver malware and steal sensitive data. The group’s repeated targeting and changing toolset suggest a sustained operation rather than a single isolated lure.

Related Happenings

Silver Fox South Asia phishing campaign

Campaign
H score34 First: 24.03.2026 18:00 Last: 24.03.2026 18:00 Sources 1

About this happening: The Silver Fox campaign now includes BYOVD abuse of a previously unknown WatchDog Anti-malware driver, amsdk.sys (version 1.0.600), to disable security tools on co...

Silver Dragon intrusion and phishing campaign targeting Europe, Southeast Asia, and Uzbekistan

Campaign
H score36 First: 04.03.2026 10:14 Last: 04.03.2026 10:14 Sources 1

About this happening: The Silver Dragon campaign is actively using public-facing internet servers and phishing emails with malicious attachments to gain initial access, expanding risk acros...

Mustang Panda multi-country espionage campaign against government and telecom targets

Campaign
H score37 First: 28.01.2026 13:40 Last: 28.01.2026 13:40 Sources 1

About this happening: Mustang Panda has run a multi-year espionage campaign since 2021, with early tradecraft centered on signed binaries and DLL side-loading against government and...

Storm-0249 tax-themed phishing campaign targeting U.S. users

Campaign
H score29 First: 09.12.2025 15:37 Last: 09.12.2025 15:37 Sources 1

About this happening: Storm-0249 ran a tax-themed phishing campaign against U.S. users ahead of the tax filing season, expanding access opportunities for downstream abuse. The operation...

STAC6565 spear-phishing campaign targeting Canadian organizations

Campaign
H score41 First: 09.12.2025 11:35 Last: 09.12.2025 11:35 Sources 1

About this happening: The STAC6565 campaign has driven almost 40 intrusions against Canadian organizations, making it a sustained operation with a sharply focused target set. Attackers use...

Timeline

  1. 02.10.2025 17:44 2 articles · 9mo ago

    Confucius Pakistan phishing campaign using WooperStealer and Anondoor

    Initial Disclosure

    The earliest documented wave used a .PPSX lure in December 2024 to deliver WooperStealer through DLL side-loading. That phase established the campaign’s reliance on phishing documents as the entry point.

    Show sources