The Confucius, active since 2013, has recently stepped up its operations by using malicious Office documents to compromise Windows with a new backdoor called AnonDoor.

Historically known for developing document-stealing malware such as WooperStealer, the threat has now transitioned to a sophisticated multi-layered infection chain that leverages OLE-embedded scripts, VBScript droppers, PowerShell loaders, and scheduled tasks to achieve persistence and evade detection.
This development underscores the team's commitment to improving its technique and targeting high-value information to government and defense organizations in South Asia.
See also: Fake Microsoft Teams installers distribute Oyster backdoor
Confucius: How does the team attack?
Initial access is primarily achieved through spear-phishing campaigns that deliver corrupted PPSX or DOCX attachments. When unsuspecting users open these documents, they encounter a “Corrupted Page” message that hides an embedded OLE object. This triggers a background download of a secondary document, mango44NX.doc, from a remote server.
Fortinet researchers noted that the CMD stub within slide1.xml.rels launches a VBScript dropper hosted on greenxeonsr.info, marking the first deployment of AnonDoor in this campaign. Once executed, the VBScript dropper performs the following steps: creates an MSXML2.XMLHTTP object to download a raw DLL payload, writes the binary to %LocalAppData%\Mapistub.dll, and then prepares for execution via DLL side-loading . The dropper also copies a legitimate executable to %AppData%\Swom.exe and writes a registry key under HKCU\Software\Microsoft\Windows\CurrentVersion\Run to ensure that the side-loaded DLL is launched on every login.
See also: North Korean hackers use new AkdoorTea backdoor
This strategy not only hides the malicious binary within trusted processes but also provides strong persistence without creating any visible traces.

Infection mechanism
The infection mechanism focuses on leveraging a malicious Office payload to smoothly insert AnonDoor. First, the document's OLE object references an external VBScript hosted on greenxeonsr.info.
The following script snippet shows how the dropper leverages ADODB.Stream to store the received bytes as a DLL.
Once the DLL is in place, the dropper invokes a reconstructed ShellExecute call to launch Swom.exe, which loads the DLL into memory. The DLL then contacts multiple C2 domains—cornfieldblue.infoand hauntedfishtree.info—to retrieve further payloads, including the WooperStealer module and additional configuration files.
This layered approach ensures that even if one stage is detected, subsequent payloads can be dynamically retrieved, parsed, and replaced, complicating investigations. By combining document-based exploitation with encrypted scripting and DLL side-loading, Confucius demonstrates advanced operational security and resilience against endpoint defenses.
See also: New backdoor attacks tech and legal sectors

Defense teams should prioritize monitoring for abnormal OLE object behavior, unexpected registry modifications, and unusual DLL loads within Office processes. Integrating heuristics that detect unusual flow entries in user directories and enforcing strict network segmentation can help address this emerging threat.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
