BackdoorDiplomacy
MITRE ATT&CK: G0135 View on attack.mitre.org
Aliases: BackDip, CloudComputating, Quarian, BackdoorDiplomacy
- First seen
- 2017-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 89 (88 malicious)
- Last IoC activity
- 2026-09-02 00:38:19
- Profile updated
- 2026-07-07 12:00:39
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:af country_code:fr country_code:eg country_code:qa
Context
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
Recent IoC activity
88 malicious indicators in Maltiverse are attributed to BackdoorDiplomacy (G0135). The 20 most recently updated:
Detection coverage
- 14 YARA rules
- 372 Sigma rules
Malware & tools used
- Obfuscated Files or Information (attack-pattern)
- Web Shell (attack-pattern)
- Exploit Public-Facing Application (attack-pattern)
- Tool (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Local Data Staging (attack-pattern)
- Network Service Discovery (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
- Non-Application Layer Protocol (attack-pattern)
- DLL (attack-pattern)
- Malware (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Turian (malware)
- China Chopper (malware)
- Mimikatz (malware)
- NBTscan (malware)
- QuasarRAT (malware)
Reports & references
- ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
- MITRE ATT&CK — G0135 (report)