BackdoorDiplomacy
An APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunication companies in Africa and the Middle East since at least 2017.
BackdoorDiplomacy is an APT group targeting Ministries of Foreign Affairs and telecoms across Africa, the Middle East, Eastern Europe, and Asia.
BackdoorDiplomacy (aka BackDip, CloudComputating, Quarian) is an APT group active since at least 2017, primarily targeting Ministries of Foreign Affairs and telecommunication companies across Africa, the Middle East, Eastern Europe, and Asia. They gain initial access by exploiting public-facing applications and deploy web shells like China Chopper for persistence, alongside custom malware such as Turian and QuasarRAT. The group uses Mimikatz and NBTscan for internal reconnaissance and lateral movement, while employing obfuscated files and non-application layer protocols for C2 communication. Defenders should prioritize patching public-facing applications, implement robust web shell detection mechanisms, and monitor for the use of post-exploitation tools like Mimikatz and NBTscan within their networks.
An APT group that we are calling BackdoorDiplomacy, due to the main vertical of its victims, has been targeting Ministries of Foreign Affairs and telecommunication companies in Africa and the Middle East since at least 2017.
Implement threat intelligence to track the development and acquisition of malware and tools.
Implement vulnerability management to detect Exploit Public-Facing Application techniques on publicly facing applications.
Monitor suspicious files and scripts on web servers to detect Web Shell.
Monitor Obfuscated Files or Information and Match Legitimate Resource Name or Location techniques to detect suspicious files and information.
Monitor Network Service Discovery and System Network Connections Discovery techniques to detect network services and connections.
Monitor local data staging to detect Local Data Staging techniques.
Monitor Non-Application Layer Protocol and Ingress Tool Transfer techniques to detect suspicious network traffic.
Defenders should prioritize patching public-facing applications.
The group uses Mimikatz and NBTscan.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.