Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BackdoorDiplomacy

Also known as: BackDip, CloudComputating, Quarian

Description

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.(Citation: ESET BackdoorDiplomacy Jun 2021)

Goals & Targeting

Targeted Sectors

Government
Telecommunications

AI Analysis

· 2 weeks ago

Executive Summary

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017, targeting government and telecommunications sectors across multiple continents. Their primary motivation appears to be gathering sensitive information. The group's operations have been observed in Africa, Europe, the Middle East, and Asia.

Goals & Targeting

The primary objectives of BackdoorDiplomacy appear to be the collection of sensitive diplomatic and strategic information from government and telecommunications entities. Their targeting profile suggests a strategic focus on destabilizing or influencing international relations through the theft of confidential communications and data. Typical victims are high-value targets within Ministries of Foreign Affairs and major telecommunications providers, indicating the group seeks to exploit vulnerabilities in these sectors for espionage purposes.

Enhanced Description

Further analysis of BackdoorDiplomacy reveals a complex and well-orchestrated approach to cyber espionage. They utilize a range of tactics, from spear-phishing and social engineering to deploying custom malware designed to remain undetected within compromised networks. Their extensive targeting of diplomatic and telecommunication entities across multiple regions suggests a broad scope of intelligence interests, potentially driven by geo-political objectives. The group's activities underscore the importance of robust cybersecurity defenses in sectors critical to national security and international relations.

Key Capabilities

  • Customized malware development
  • Social engineering and phishing operations
  • Network exploitation and persistence
  • Data exfiltration and encryption
  • Evasion techniques for avoiding detection

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation

ATT&CK Techniques

T1059.003
T1055
T1566.001

Software / Tooling

Custom RAT
Living off the Land (LOTL) tactics

Campaigns & Victims

BackdoorDiplomacy's campaign patterns suggest a patient and calculated approach, with operations spanning months or even years. They typically target specific sectors and countries, often leveraging local events or diplomatic tensions to their advantage. Notable past operations have involved the use of zero-day exploits and highly customized malware, indicating significant resources and expertise. Their operational tempo is characterized by periods of high activity followed by dormancy, making detection and attribution challenging.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting

Recommended Actions

  • Enhance email security with sandboxing and behavioral analysis
  • Implement robust access controls and monitoring for privileged accounts
  • Regularly update and patch software vulnerabilities, especially in high-risk sectors
  • Utilize advanced threat detection tools with AI-driven anomaly detection

Suggested Tags

APT
Cyber Espionage
Government Targeting
Telecommunications Sector

Confidence Assessment

The confidence in the available data on BackdoorDiplomacy is moderate to high, given the group's observed activities and the analysis of their TTPs. However, information gaps exist regarding their exact motivations, the full scope of their operations, and the identities of those behind the group. Continuous monitoring and further research are necessary to fill these gaps and understand the evolving threat landscape posed by BackdoorDiplomacy.

ATT&CK Techniques

Stealth
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. ESET BackdoorDiplomacy Jun 2021 — Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

Intel Summary

15

Techniques

2

Tools

0

Campaigns

0

IOCs

0

Observed Data

7

Tactics

Tags

APT
Backdoor / C2

Details

MITRE ID
G0135
Type
Unknown
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--9735c036-8ebe-47e9-9c77-b0ae656dab93
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.