Researchers linked intrusions at telecom organizations in South Asia and an ISP in West Asia to CloudComputating—also tracked as BackdoorDiplomacy and Faking Dragon—after uncovering a new modular malware framework called QSC. The framework was delivered through Quarian v3 (also known as Turian) and consists of Loader, Core, Network, Command Shell, and File Manager components designed to keep most functionality in memory. In a later campaign, the attackers also deployed a new Golang backdoor, GoClient, to execute commands, manage files, capture screenshots, and conduct post-compromise reconnaissance.
The operators used QSC and GoClient to enumerate compromised environments, identify domain controllers and file servers, steal NTDS.dit using shadow copies, and move laterally with WMIC and stolen domain administrator credentials. Researchers said the activity showed a tactical shift toward a plugin-based framework with internal pivoting and port-forwarding to route command-and-control traffic through compromised hosts. The attribution to CloudComputating was made with medium confidence based on Quarian infrastructure, malware overlaps, shared tooling, and consistent operational patterns.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Based on Quarian infrastructure, malware similarities, shared tooling, and operational patterns, researchers assessed with medium confidence that the activity was conducted by the CloudComputating group, also known as BackdoorDiplomacy or Faking Dragon. The report described this as an evolution toward a plugin-based framework that keeps most functionality in memory.
In the 2023 campaign against an ISP in West Asia, the attackers introduced a new Golang backdoor called GoClient. It supported command execution, file operations, screenshots, and post-compromise reconnaissance.
Researchers investigating intrusions at telecom organizations in South Asia uncovered QSC, a modular in-memory malware framework deployed via the Quarian v3 backdoor. The framework consisted of Loader, Core, Network, Command Shell, and File Manager modules.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 36 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.