APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Confucius (aka Confucius, Confucius APT) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Confucius
G0142
APT
IN · India
AKA
Confucius APT
CrowdStrike
:
PANDA SPIDER
MITRE
:
G0142
Targets
1
Sectors
3
Threat types
1
GIRs covered
0/480
Active since
2013
Pin to atlas
Watch
Share
Export
Also tracked as
2 vendor names · 1 other aliases
Open Rosetta Stone
CrowdStrike
PANDA SPIDER
MITRE
G0142
UNATTRIBUTED ALIASES
Confucius APT
Victimology
Geographic footprint · 1 countries
Region filter
Export
origin · India
targeted countries · 1
ASIA ·
1
Pakistan
Sectors targeted
3 of 40
Government
100 actors
Defense
72 actors
Telecom
72 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 18 techniques
Resource Development
· 1
T1583.006
Web Services
Initial Access
· 2
T1566.001
Spearphishing Attachment
T1566.002
Spearphishing Link
Execution
· 5
T1053.005
Scheduled Task
Persistence
· 1
Discovery
· 2
T1083
File and Directory Discovery
Collection
· 1
T1119
Automated Collection
Exfiltration
· 2
T1041
Exfiltration Over C2 Channel
T1567.002
Exfiltration to Cloud Storage
Command And Control
· 2
T1071.001
Web Protocols
Stealth
· 2
T1218.005
Mshta
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
18 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1059.001
PowerShell
T1059.005
Visual Basic
T1203
Exploitation for Client Execution
T1204.001
Malicious Link
T1547.001
Registry Run Keys / Startup Folder
T1680
Local Storage Discovery
T1105
Ingress Tool Transfer
T1221
Template Injection