Overview 67 indicators
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
| domain | 67 | G0135-domain.txt |
Techniques 15 ATT&CK
Open in ATT&CK Navigator → or download the layer (15 techniques, layer 4.5)
- T1027 Obfuscated Files or Information
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1055.001 Dynamic-link Library Injection
- T1074.001 Local Data Staging
- T1095 Non-Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1120 Peripheral Device Discovery
- T1190 Exploit Public-Facing Application
- T1505.003 Web Shell
- T1574.001 DLL
- T1588.001 Malware
- T1588.002 Tool
Software 5
Principal sources 7 reports
Ranked by how many of this actor's indicators each report brought in.
- 35bitdefender.com/files/News/CaseStudies/study/426/Bitdef…
- 35otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
- 23welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-…
- 23otx.alienvault.com/pulse/60c341dc8964edd2e2fcb651
- 7unit42.paloaltonetworks.com/playful-taurus
- 7otx.alienvault.com/pulse/63c82cfb80f9e85b9b69c3cc
- 2github.com/advanced-threat-research/IOCs/blob/mast…
Timeline 67 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
unit42.paloaltonetworks.com/playful-taurus · otx.alienvault.com/pulse/63c82cfb80f9e85b9b69c3cc
adboeonline.net mfaantivirus.xyz pfs1010.com pfs1010.xyz scm.oracleapps.org update.adboeonline.net update.delldrivers.in -
bitdefender.com/files/News/CaseStudies/study/426/Bitdef… · otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
250f7cloud.crmdev.org 29c04uc.ejalase.org 62ffauc.ejalase.org 7f4d9fcanet.microsoftshop.org alberto2011.com cloud.fastpaymentser-vice.com cloud.microsoftshop.org cloud.skypecloud.net crmdev.org delldrivers.in efanshion.com ejalase.org fastpaymentser-vice.com fazlol-lah.net info.fazlol-lah.net info.payamra-dio.com info.payamradio.com irir.org mail.irir.org mci.ejalase.org microsoftshop.org news.alberto2011.com oracleapps.org payamra-dio.com payamradio.com picture.efanshion.com plastic.delldrivers.in proxy.oracleapps.org skypecloud.net srv.payamradio.com support.vpnkerio.com uc.ejalase.org -
welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-… · otx.alienvault.com/pulse/60c341dc8964edd2e2fcb651
microsoftbuys.com officenews365.com vpnkerio.com worldmessg.com -
bitdefender.com/files/News/CaseStudies/study/426/Bitdef… · otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
info.fazlollah.net srv.fazlollah.net -
bitdefender.com/files/News/CaseStudies/study/426/Bitdef… · otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
fazlollah.net -
welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-… · otx.alienvault.com/pulse/60c341dc8964edd2e2fcb651
bill.microsoftbuys.com buffetfactory.oicp.io dnsupdate.dns1.us dnsupdate.dns2.us dynsystem.imbbs.in freedns02.dns2.us icta.worldmessg.com intelupdate.dns1.us officeupdate.ns01.us officeupdates.cleansite.us pmdskm.top systeminfo.cleansite.info systeminfo.myftp.name systeminfo.oicp.net szsz.pmdskm.top update.officenews365.com updateip.onmypc.net web.vpnkerio.com winupdate.ns02.us -
github.com/advanced-threat-research/IOCs/blob/mast…
andyothers.acmetoy.com keep.ns3.name
Further reading 8
- attack.mitre.org/groups/G0135
- welivesecurity.com/2021/06/10/backdoordiplomacy-upgrading-…
- otx.alienvault.com/pulse/60c341dc8964edd2e2fcb651
- otx.alienvault.com/pulse/6390cbe098c9fb94d48e7a1c
- unit42.paloaltonetworks.com/playful-taurus
- otx.alienvault.com/pulse/63c82cfb80f9e85b9b69c3cc
- bitdefender.com/files/News/CaseStudies/study/426/Bitdef…
- github.com/advanced-threat-research/IOCs/blob/mast…