BackdoorDiplomacy
BackdoorDiplomacy is a Chinese threat actor associated with cyberespionage activity. Reporting in the provided content describes it as a Chinese state-sponsored or Chinese-aligned actor, with overlap or a close relationship noted with APT15 and additional overlap reported with Playful Taurus, Vixen Panda, NICKEL, and Ke3chang. Sophos also identified overlap between activity in its Crimson Palace Cluster Alpha and prior reporting on BackdoorDiplomacy. The group has targeted government entities as well as high-priority telecommunications and finance organizations. The content specifically notes operations across Africa for several years, including targeting linked to South Africa, Kenya, Senegal, and Ethiopia, as well as activity in the Middle East. Recent reporting cited in the content describes a sustained three-year campaign against governmental organizations in Kenya. Tradecraft described in the content includes exploitation of public-facing applications and misconfigurations for initial access, including CVE-2020-5902 in F5 BIG-IP to drop a Linux backdoor and exploitation of misconfigured Plesk servers. The content also associates BackdoorDiplomacy with web shell and IIS-component-related persistence, command and scripting interpreter use, and malware/tool upload activity in ATT&CK annotations. Operational behaviors mentioned include obtaining and using leaked malware such as DoublePulsar, EternalBlue, EternalRocks, and EternalSynergy; using SMBTouch to determine whether targets were vulnerable to EternalBlue; obtaining open-source reconnaissance and red-team tools for discovery and lateral movement; obfuscating tools and malware with VMProtect; dropping implants in folders named for legitimate software; copying files of interest to the main drive's Recycle Bin for staging; and using an executable to detect removable media such as USB flash drives. The content also notes a sideloading chain resembling one used to deploy a Merlin Agent by BackdoorDiplomacy.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
41 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
Associated vulnerabilities
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
4 more CVEs tied to this actor tracked in Mallory.
Observables
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with IIS-related exploitation and IIS component persistence detections.
Listed as a threat actor associated with exploitation of public-facing applications and malware/tool upload activity relevant to Confluence exploitation detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.