BackdoorDiplomacy is a Chinese state-linked cyberespionage threat actor associated with long-running intrusions against government, telecommunications, and financial organizations. Reporting has linked the group to operations in Africa, the Middle East, and Southeast Asia, with notable targeting in Kenya, Ethiopia, Senegal, South Africa, and a high-profile Southeast Asian government environment. The actor is assessed to pursue strategic intelligence collection aligned with Chinese state interests. BackdoorDiplomacy has been reported to overlap with or maintain relationships to other Chinese intrusion clusters and aliases including APT15, Ke3chang, NICKEL, Playful Taurus, and Vixen Panda. The group is known for exploiting public-facing applications for initial access and for maintaining persistence through web shells and extensive abuse of DLL side-loading and DLL search order hijacking. It has repeatedly used legitimate signed software and trusted executables to load malicious DLLs, dropped implants into directories named after legitimate software, and disguised tooling to blend into victim environments. BackdoorDiplomacy has also used VMProtect to obfuscate malware and tools, reflecting a consistent emphasis on defense evasion. Operationally, BackdoorDiplomacy conducts multi-stage intrusions in which compromised hosts are used to download additional payloads and post-compromise tooling. The actor has obtained and repurposed leaked offensive capabilities, including malware and exploit tooling associated with EternalBlue-era tradecraft, and has used vulnerability-scanning utilities to identify susceptible targets. It has also leveraged open-source reconnaissance and red-team tools for discovery and lateral movement. Observed post-compromise behavior includes removable-media discovery, local staging of files of interest prior to theft, and execution of malicious DLLs through legitimate software. The group has copied collected data into staging locations before exfiltration and has demonstrated broad reconnaissance and internal movement capabilities consistent with espionage-focused operations rather than disruptive or financially motivated campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
BackdoorDiplomacy has exploited CVE-2020-5902, an F5 BIP-IP vulnerability, to drop a Linux backdoor.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
The following analytic detects attempts to exploit CVE-2022-26134, an unauthenticated remote code execution vulnerability in Confluence... This activity is significant as it allows attackers to execute arbitrary code on the Confluence server without authentication, potentially leading to full system compromise.
4 more CVEs tied to this actor tracked in Mallory.
19 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed in detection annotations as associated with T1190; no further details provided.
Listed as an associated threat actor in the detection annotation for exploitation of the public-facing PTC Windchill vulnerability CVE-2026-4681.
Listed as a threat actor associated with the PowerShell P/Invoke process injection API chain detection and related ATT&CK techniques.
Listed as a threat actor associated with IIS-related exploitation and IIS component persistence detections.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.