HomeSecurityConfucius targets Windows systems with the AnonDoor backdoor

Confucius targets Windows systems with AnonDoor backdoor

The Confucius, active since 2013, has recently stepped up its operations by using malicious Office documents to compromise Windows with a new backdoor called AnonDoor.

Confucius Windows backdoor AnonDoor

Historically known for developing document-stealing malware such as WooperStealer, the threat has now transitioned to a sophisticated multi-layered infection chain that leverages OLE-embedded scripts, VBScript droppers, PowerShell loaders, and scheduled tasks to achieve persistence and evade detection.

This development underscores the team's commitment to improving its technique and targeting high-value information to government and defense organizations in South Asia.

See also: Fake Microsoft Teams installers distribute Oyster backdoor

Confucius: How does the team attack?

Initial access is primarily achieved through spear-phishing campaigns that deliver corrupted PPSX or DOCX attachments. When unsuspecting users open these documents, they encounter a “Corrupted Page” message that hides an embedded OLE object. This triggers a background download of a secondary document, mango44NX.doc, from a remote server.

Fortinet researchers noted that the CMD stub within slide1.xml.rels launches a VBScript dropper hosted on greenxeonsr.info, marking the first deployment of AnonDoor in this campaign. Once executed, the VBScript dropper performs the following steps: creates an MSXML2.XMLHTTP object to download a raw DLL payload, writes the binary to %LocalAppData%\Mapistub.dll, and then prepares for execution via DLL side-loading . The dropper also copies a legitimate executable to %AppData%\Swom.exe and writes a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run to ensure that the side-loaded DLL is launched on every login.

See also: North Korean hackers use new AkdoorTea backdoor

This strategy not only hides the malicious binary within trusted processes but also provides strong persistence without creating any visible traces.

Confucius targets Windows systems with AnonDoor backdoor

Infection mechanism

The infection mechanism focuses on leveraging a malicious Office payload to smoothly insert AnonDoor. First, the document's OLE object references an external VBScript hosted on greenxeonsr.info.

The following script snippet shows how the dropper leverages ADODB.Stream to store the received bytes as a DLL.

Once the DLL is in place, the dropper invokes a reconstructed ShellExecute call to launch Swom.exe, which loads the DLL into memory. The DLL then contacts multiple C2 domains—cornfieldblue.infoand hauntedfishtree.info—to retrieve further payloads, including the WooperStealer module and additional configuration files.

This layered approach ensures that even if one stage is detected, subsequent payloads can be dynamically retrieved, parsed, and replaced, complicating investigations. By combining document-based exploitation with encrypted scripting and DLL side-loading, Confucius demonstrates advanced operational security and resilience against endpoint defenses.

See also: New backdoor attacks tech and legal sectors

Graphican backdoor

Defense teams should prioritize monitoring for abnormal OLE object behavior, unexpected registry modifications, and unusual DLL loads within Office processes. Integrating heuristics that detect unusual flow entries in user directories and enforcing strict network segmentation can help address this emerging threat.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS