ATT&CKGroupsBackdoorDiplomacy

BackdoorDiplomacy

G0135

Threat group.View on attack.mitre.org

About this group

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.

Techniques used15

Procedure examples15

TechniqueProcedure example
T1027
Obfuscated Files or Information

BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect.

T1036.004
Masquerade Task or Service

BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations.

T1036.005
Match Legitimate Resource Name or Location

BackdoorDiplomacy has dropped implants in folders named for legitimate software.

T1046
Network Service Discovery

BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware.

T1049
System Network Connections Discovery

BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports.

T1055.001
Dynamic-link Library Injection

BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs.

T1074.001
Local Data Staging

BackdoorDiplomacy has copied files of interest to the main drive's recycle bin.

T1095
Non-Application Layer Protocol

BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities.

T1105
Ingress Tool Transfer

BackdoorDiplomacy has downloaded additional files and tools onto a compromised host.

T1120
Peripheral Device Discovery

BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives.

T1190
Exploit Public-Facing Application

BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor. BackdoorDiplomacy has also exploited mis-configured Plesk servers.

T1505.003
Web Shell

BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system.

T1574.001
DLL

BackdoorDiplomacy has executed DLL search order hijacking.

T1588.001
Malware

BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations.

T1588.002
Tool

BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement.

Software5

Campaigns0

None recorded.

References1

  1. ESET BackdoorDiplomacy Jun 2021 Open source
    Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.