BackdoorDiplomacy

APT / StateG0135 ↗
Techniques (MITRE ATT&CK)15
SourceMITRE ATT&CK
Target categories: Government, Telecomms
Targeted regions: Libya · Namibia · Sudan · Albania · Croatia · Georgia · Poland · Iran · Qatar · Saudi Arabia +2
Also known as:BackDipCloudComputatingQuarian

About the group

BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity45
Impact: High
T1190T1505.003T1046ENTRYInitial accessExploitPublic-Facing App…PERSPersistenceWeb ShellDISCDiscoveryNetwork ServiceDiscoveryCOLLCollectionLocal Data Staging

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 475

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port192.162.199.218:2222Quasar RATthreatfox
ip:port114.66.20.236:8008Quasar RATthreatfox
ip:port31.59.39.40:4545Quasar RATthreatfox
sha256_hashc734e31036a2ef2d09b93028828ab08c79afb47c06d125f16af87706e58f2609Quasar RATthreatfox
sha1_hash5b95bcc4f60d8653f0374f607d7ce67b1b5a2817Quasar RATthreatfox
md5_hash82a4bd3e8d17ab61c6fb376bdaa08eddQuasar RATthreatfox
sha1_hashefbd76e4dbff0ad6829758fcafe26ce911722322Quasar RATthreatfox
sha256_hash16c90a2348c565940e936cbdb37014e539d0533acc47700c81c4f281a91f9535Quasar RATthreatfox
md5_hash36cf6285b152d569a123b34f6a08d892Quasar RATthreatfox
sha256_hash7676fde665253b1ed960e2e444f00c1a27a90cc159350da68624936891a82e38QuasarRATmalwarebazaar
urlhttps://github.com/thuhangn562727-del/maqueo/raw/refs/heads/main/gaylo.exeQuasarRATurlhaus
ip:port186.169.33.226:6001Quasar RATthreatfox
sha256_hashb482ef65f7b4a5fd31fa82079f33dce56471710b5049f78e794dfac0cdb823c8Quasar RATthreatfox
sha256_hash446150a7841e85746ef4209c550853445d4ff2625242b2f2d62c0c34f30756f8QuasarRATmalwarebazaar
ip:port185.233.164.83:3306Quasar RATthreatfox
ip:port45.43.163.202:4782Quasar RATthreatfox
ip:port110.42.111.42:8008Quasar RATthreatfox
domainkekmannetje.ddns.netQuasar RATthreatfox
domainwww.mb66.kidsQuasar RATthreatfox
domainwww.8kbet.shQuasar RATthreatfox
domainfb88dangnhap.inQuasar RATthreatfox
domainmb66.kidsQuasar RATthreatfox
ip:port188.132.232.169:443Quasar RATthreatfox
ip:port5.175.192.52:4782Quasar RATthreatfox
ip:port94.46.237.232:4444Quasar RATthreatfox
ip:port5.175.192.24:4782Quasar RATthreatfox
ip:port213.5.130.233:4782Quasar RATthreatfox
ip:port5.175.169.133:4782Quasar RATthreatfox
ip:port93.185.165.94:4380Quasar RATthreatfox
ip:port196.251.121.52:56001Quasar RATthreatfox

+475 indicators in total. See them all on the IOCs page.

BackdoorDiplomacy uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →