BackdoorDiplomacy

APT / StateG0135
Techniques (MITRE ATT&CK)15
SourceMITRE ATT&CK
Target categories: Government, Telecomms
Targeted regions: Libya · Namibia · Sudan · Albania · Croatia · Georgia · Poland · Iran · Qatar · Saudi Arabia +2

Vexday analysis

Ativo desde pelo menos 2017, o BackdoorDiplomacy (identificador MITRE ATT&CK G0135) é um grupo de espionagem cibernética que tem como alvos Ministérios de Relações Exteriores e empresas de telecomunicações na África, Europa, Oriente Médio e Ásia. O grupo possui 15 técnicas documentadas no MITRE ATT&CK e é associado à exploração de 3 CVEs conhecidas.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity45
Impact: High
T1190T1505.003T1046ENTRYInitial accessExploitPublic-Facing App…PERSPersistenceWeb ShellDISCDiscoveryNetwork ServiceDiscoveryCOLLCollectionLocal Data Staging

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 3

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 113

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port134.122.200.208:8088Quasar RATthreatfox
ip:port134.122.200.212:8088Quasar RATthreatfox
ip:port94.154.34.203:1604Quasar RATthreatfox
md5_hash8ad256c5b786abb5f1552d906df3482aQuasar RATthreatfox
sha1_hashc321593cb3d8e279dfbdcf6d8bb94fac93cdc405Quasar RATthreatfox
sha256_hashb3c2f9ac068664bb861d7f8a59db533810032bc26d75fad48dbd0e2ba26413b2Quasar RATthreatfox
ip:port153.52.162.73:8080Quasar RATthreatfox
ip:port169.58.23.30:22Quasar RATthreatfox
domainvk10.waizerfly.comQuasar RATthreatfox
ip:port202.181.188.64:1488Quasar RATthreatfox
ip:port194.59.30.105:9619Quasar RATthreatfox
ip:port134.122.200.217:8088Quasar RATthreatfox
ip:port20.215.224.217:8080Quasar RATthreatfox
ip:port5.83.150.71:4567Quasar RATthreatfox
ip:port145.63.135.73:4782Quasar RATthreatfox
ip:port178.16.52.35:4433Quasar RATthreatfox
ip:port190.255.83.163:6001Quasar RATthreatfox
urlhttp://217.60.195.219/ty/load.batQuasarRATurlhaus
ip:port5.230.69.252:8443Quasar RATthreatfox
ip:port38.128.251.209:3000Quasar RATthreatfox
ip:port105.108.207.177:288Quasar RATthreatfox
ip:port185.194.30.165:8080Quasar RATthreatfox
ip:port149.30.232.214:46999Quasar RATthreatfox
ip:port20.215.40.6:7000Quasar RATthreatfox
ip:port130.162.224.102:2222Quasar RATthreatfox
md5_hash2ac1f830806ce3bdd35cdcb957f139baQuasar RATthreatfox
sha1_hash00f6a68fef995c15c116c48b18d9611db036c1e5Quasar RATthreatfox
sha256_hash9270d36aa57eec3d44dc2d66929551198cb8a31d0ef383a726c38b75ad8144baQuasar RATthreatfox
ip:port194.59.30.130:5000Quasar RATthreatfox
ip:port38.128.251.36:3000Quasar RATthreatfox

+113 indicators in total. See them all on the IOCs page.

BackdoorDiplomacy uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →