BackdoorDiplomacy

MITRE ATT&CK: G0135 View on attack.mitre.org

Aliases: BackDip, CloudComputating, Quarian, BackdoorDiplomacy

First seen
2017-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
89 (88 malicious)
Last IoC activity
2026-09-02 00:38:19
Profile updated
2026-07-07 12:00:39

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:af country_code:fr country_code:eg country_code:qa

Context

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.

Recent IoC activity

88 malicious indicators in Maltiverse are attributed to BackdoorDiplomacy (G0135). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname mfaantivirus.xyz 2026-09-03 1
hostname microsoftshop.org 2026-09-02 1
hostname pfs1010.com 2026-09-02 1
hostname pfs1010.xyz 2026-09-02 1
hostname 29c04uc.ejalase.org 2026-08-06 1
hostname srv.fazlollah.net 2026-07-31 2
hostname update.adboeonline.net 2026-07-22 1
hostname news.alberto2011.com 2026-07-21 1
hostname mci.ejalase.org 2026-07-12 1
hostname 7f4d9fcanet.microsoftshop.org 2026-07-01 1
hostname scm.oracleapps.org 2026-06-26 1
file sample ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58 2026-06-25 1
hostname delldrivers.in 2026-06-18 1
hostname info.fazlollah.net 2026-04-18 1
hostname vpnkerio.com 2026-04-16 2
file sample 20230118_67c911510e257b34.exe_ 2026-02-10 3
file sample 8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3 2025-12-17 1
hostname mail.indiarailways.net 2025-10-25 1
hostname picture.efanshion.com 2025-10-20 2
file sample 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa 2025-09-30 2

Detection coverage

  • 14 YARA rules
  • 372 Sigma rules

Malware & tools used

  • Obfuscated Files or Information (attack-pattern)
  • Web Shell (attack-pattern)
  • Exploit Public-Facing Application (attack-pattern)
  • Tool (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Network Service Discovery (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)
  • Non-Application Layer Protocol (attack-pattern)
  • DLL (attack-pattern)
  • Malware (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Turian (malware)
  • China Chopper (malware)
  • Mimikatz (malware)
  • NBTscan (malware)
  • QuasarRAT (malware)

Reports & references

  • ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
  • MITRE ATT&CK — G0135 (report)

External references