WooperStealer is an information-stealing malware used by the Confucius espionage group in campaigns targeting Pakistan and, more broadly, government, military, defense contractor, and critical-industry organizations in South Asia. Reporting places its use in at least December 2024 through March 2025, after which Confucius was observed shifting toward the Python-based backdoor AnonDoor/Anondoor.
Observed infection chains delivered WooperStealer through phishing lures using weaponized .PPSX files and later malicious .LNK attachments disguised as documents. In the documented chains, execution relied on DLL side-loading via renamed copies of the legitimate Windows utility fixmapi.exe, including filenames such as Swom.exe and BlueAle.exe, to load malicious DLLs such as Mapistub.dll. One December 2024 campaign used a PPSX attachment that triggered an embedded OLE object, which fetched a VBScript dropper from greenxeonsr[.]info; the dropper downloaded Mapistub.dll, established persistence via HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load, and launched the sideloading chain. A later LNK-based chain downloaded mapistub.dll and a decoy PDF from petricgreen[.]info and also used persistence mechanisms involving registry entries and the C:\Windows\Tasks directory.
WooperStealer was identified in reporting by the string Class1.Wooper / stringToEscape variable. Its primary capability is theft of files from infected systems. It enumerates logical drives, collects a broad set of file types, and exfiltrates them to attacker-controlled infrastructure. Reported targeted extensions include documents, images, email files, and archives, with examples including .txt, .pdf, .doc, .docx, .xls, .xlsx, .ppt, .png, .jpeg, .pst, .zip, and .rar. In one analyzed sample, stolen data was uploaded to hxxp://marshmellowflowerscar[.]info. Fortinet also reported exfiltration via HTTP POST parameters containing victim identifiers in the format <SerialNumber><ComputerName><UserName>, along with file path and file hash values to avoid duplicate uploads.
Associated infrastructure mentioned in the reporting includes greenxeonsr[.]info, cornfieldblue[.]info, hauntedfishtree[.]info, petricgreen[.]info, and marshmellowflowerscar[.]info. High-confidence indicators directly tied to the broader Confucius tooling around WooperStealer include the hash abefd29c85d69f35f3cf8f5e6a2be76834416cc43d87d1f6643470b359ed4b1b, reported in the context of the Confucius Anondoor framework that was observed loading WooperStealer as a component.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This weapon not only loaded the wooperstealer that was used in the ADS attack in 2024 [1], but also upgraded the previous stage of the downloader Trojan to a componentized backdoor.
5 distinct techniques documented for this family, organized by ATT&CK tactic.
The communication addresses of all components are passed through the anondoor parameter... by using the parameterized C2 (Command and Control) communication mechanism
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Confucius APT Evolves: Espionage Group Shifts from WooperStealer to Advanced Python Backdoor AnonDoor
Document-stealing infostealer used to collect targeted file types (e.g., .txt, .pdf, .doc, .xls, .png, .jpeg, .ppt, .zip) and exfiltrate them to a remote URL. Delivered via lure documents/LNK attachments with staged components and DLL sideloading into a renamed fixmapi.exe.
Information-stealing malware used by Confucius to enumerate drives, collect targeted document/archive/email file types, and exfiltrate them to attacker-controlled infrastructure. In later samples it uses POST uploads with victim identifiers and a file-hash check to avoid re-uploading duplicates.
Information-stealing malware used by the Confucius APT as an ultimate payload in earlier campaigns against Pakistani targets, delivered via spear-phishing chains involving malicious documents and (in some cases) DLL sideloading and LNK files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.