Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
15
techniques
5
software
10,977
corpus matches
profile
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
techniques
15 attributed · most-instrumented first
Ingress Tool Transfer
command-and-control
Tool
resource-development
Match Legitimate Resource Name or Location
stealth
Exploit Public-Facing Application
initial-access
DLL
stealth · execution
System Network Connections Discovery
+3 more techniques
software
5 malware & tools attributed
Mimikatz
S0002
China Chopper
S0020
QuasarRAT
S0262
NBTscan
S0590
Turian
S0647
read this carefully
10,977 corpus matches is not attribution
That count is indicators which exhibit techniques BackdoorDiplomacy is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
discovery
showing 30 of 10,977