Sobre el grupo
BackdoorDiplomacy is a cyber espionage threat group that has been active since at least 2017. BackdoorDiplomacy has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe, the Middle East, and Asia.
Cadena de ataque
Escenario plausible montado a partir de las técnicas reales del grupo, ordenadas por las fases de un ataque. Cada etapa muestra cómo suele actuar el grupo.
Cadena ilustrativa derivada de las técnicas documentadas en MITRE ATT&CK — no representa un ataque específico ya ocurrido. La severidad resume el arsenal conocido (cobertura de la cadena, CVEs en explotación activa, técnicas).
Técnicas (MITRE ATT&CK) 15
Cómo opera el grupo, mapeado por la matriz MITRE ATT&CK y organizado por las fases de un ataque.
Vulnerabilidades explotadas 3
CVEs que este grupo es conocido por explotar, según MITRE ATT&CK. Ordenadas por gravedad real.
Infraestructura conocida 475
Indicadores reales (C2, dominios, URLs y hashes) asociados al malware que usa este grupo. Fuente: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
192.162.199.218:2222Quasar RATthreatfox114.66.20.236:8008Quasar RATthreatfox31.59.39.40:4545Quasar RATthreatfoxc734e31036a2ef2d09b93028828ab08c79afb47c06d125f16af87706e58f2609Quasar RATthreatfox5b95bcc4f60d8653f0374f607d7ce67b1b5a2817Quasar RATthreatfox82a4bd3e8d17ab61c6fb376bdaa08eddQuasar RATthreatfoxefbd76e4dbff0ad6829758fcafe26ce911722322Quasar RATthreatfox16c90a2348c565940e936cbdb37014e539d0533acc47700c81c4f281a91f9535Quasar RATthreatfox36cf6285b152d569a123b34f6a08d892Quasar RATthreatfox7676fde665253b1ed960e2e444f00c1a27a90cc159350da68624936891a82e38QuasarRATmalwarebazaarhttps://github.com/thuhangn562727-del/maqueo/raw/refs/heads/main/gaylo.exeQuasarRATurlhaus186.169.33.226:6001Quasar RATthreatfoxb482ef65f7b4a5fd31fa82079f33dce56471710b5049f78e794dfac0cdb823c8Quasar RATthreatfox446150a7841e85746ef4209c550853445d4ff2625242b2f2d62c0c34f30756f8QuasarRATmalwarebazaar185.233.164.83:3306Quasar RATthreatfox45.43.163.202:4782Quasar RATthreatfox110.42.111.42:8008Quasar RATthreatfoxkekmannetje.ddns.netQuasar RATthreatfoxwww.mb66.kidsQuasar RATthreatfoxwww.8kbet.shQuasar RATthreatfoxfb88dangnhap.inQuasar RATthreatfoxmb66.kidsQuasar RATthreatfox188.132.232.169:443Quasar RATthreatfox5.175.192.52:4782Quasar RATthreatfox94.46.237.232:4444Quasar RATthreatfox5.175.192.24:4782Quasar RATthreatfox213.5.130.233:4782Quasar RATthreatfox5.175.169.133:4782Quasar RATthreatfox93.185.165.94:4380Quasar RATthreatfox196.251.121.52:56001Quasar RATthreatfox+475 indicadores en total. Míralos todos en la página de IOCs.
Referencias
El grupo BackdoorDiplomacy usa técnicas y explota fallas reales. El Pentest Autónomo con IA de TrueHacking simula esos ataques en tu infraestructura y aporta más seguridad a tu aplicación.
Conocer el Pentest Autónomo con IA →