BackdoorDiplomacy

Also known as: BackDip, BackdoorDiplomacy, CloudComputating, Quarian

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia. ESET BackdoorDiplomacy Jun 2021

🌍 Country China
🧭 ATT&CK G0135
Government Telecomms

Introduction

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia. ESET BackdoorDiplomacy Jun 2021

Activities and Tactics

Targeted Sectors: Government, Telecomms

Country of Origin: πŸ‡¨πŸ‡³ China

Suspected Victims: Libya, Namibia, Sudan, Albania, Croatia, Georgia, Poland, Iran, Qatar, Saudi Arabia…

Notable Campaigns

Information pending cataloguing.

Tactics, Techniques, and Procedures (TTPs)

ATT&CK technique IDs (denormalized)

Notable Indicators of Compromise (IOCs)

No curated IOCs are currently published for this actor. This section will be updated when stable, attributable indicators are available.

Malware and Tools

  • Backdoor.Oldrea
  • Quarian:
  • Turian:
  • Follina:

MITRE ATT&CK Software

Attribution and Evidence

Country of Origin: China Additional attribution information pending cataloguing.

References

[1] mitre-attack [2] ESET BackdoorDiplomacy Jun 2021 Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021