Threat group.View on attack.mitre.org
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
| Technique | Procedure example |
|---|---|
| T1027 Obfuscated Files or Information |
BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. |
| T1036.004 Masquerade Task or Service |
BackdoorDiplomacy has disguised their backdoor droppers with naming conventions designed to blend into normal operations. |
| T1036.005 Match Legitimate Resource Name or Location |
BackdoorDiplomacy has dropped implants in folders named for legitimate software. |
| T1046 Network Service Discovery |
BackdoorDiplomacy has used SMBTouch, a vulnerability scanner, to determine whether a target is vulnerable to EternalBlue malware. |
| T1049 System Network Connections Discovery |
BackdoorDiplomacy has used NetCat and PortQry to enumerate network connections and display the status of related TCP and UDP ports. |
| T1055.001 Dynamic-link Library Injection |
BackdoorDiplomacy has dropped legitimate software onto a compromised host and used it to execute malicious DLLs. |
| T1074.001 Local Data Staging |
BackdoorDiplomacy has copied files of interest to the main drive's recycle bin. |
| T1095 Non-Application Layer Protocol |
BackdoorDiplomacy has used EarthWorm for network tunneling with a SOCKS5 server and port transfer functionalities. |
| T1105 Ingress Tool Transfer |
BackdoorDiplomacy has downloaded additional files and tools onto a compromised host. |
| T1120 Peripheral Device Discovery |
BackdoorDiplomacy has used an executable to detect removable media, such as USB flash drives. |
| T1190 Exploit Public-Facing Application |
BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor. BackdoorDiplomacy has also exploited mis-configured Plesk servers. |
| T1505.003 Web Shell |
BackdoorDiplomacy has used web shells to establish an initial foothold and for lateral movement within a victim's system. |
| T1574.001 DLL |
BackdoorDiplomacy has executed DLL search order hijacking. |
| T1588.001 Malware |
BackdoorDiplomacy has obtained and used leaked malware, including DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy, in its operations. |
| T1588.002 Tool |
BackdoorDiplomacy has obtained a variety of open-source reconnaissance and red team tools for discovery and lateral movement. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.