BackdoorDiplomacy, also tracked as CloudComputating and Faking Dragon, is a Chinese-speaking espionage threat actor associated with long-running intrusions against diplomatic, government, telecommunications, and internet service provider targets, particularly in the Middle East, Africa, South Asia, and West Asia. The actor has been linked to operations involving Quarian (also known as Turian), PlugX, a modular in-memory framework known as QSC, and a Golang backdoor referred to as GoClient. Activity attributed to this cluster has also involved tooling such as TailorScan and StowProxy. The group is notable for post-compromise tradecraft centered on stealthy in-memory execution, modular payloads, and internal network pivoting. QSC consists of loader, core, networking, command shell, and file-management components that are decompressed, reflectively loaded, and executed in memory. The framework supports host profiling, interactive command execution, file browsing and transfer, and configurable command-and-control routing, including use of internal proxy or pivot hosts. GoClient has been used for command execution, file operations, screenshot capture, self-deletion, and reconnaissance. Observed operations show strong emphasis on enterprise and domain-wide compromise. The actor has enumerated systems and domain resources, identified domain controllers and file servers, queried privileged groups, stolen directory database material via shadow-copy abuse, and moved laterally using WMIC and stolen administrator credentials, including pass-the-hash-style activity. CloudComputating has also modified Windows services for persistence, used webshell-enabled initial access in some Exchange exploitation chains, and deployed port-forwarding utilities to relay command-and-control traffic through compromised internal hosts. Victimology and operational history indicate a primary espionage mission. Reported targeting includes high-profile Middle Eastern diplomatic entities, governments in the Middle East and Africa, telecommunications organizations in South Asia, and an ISP in West Asia. The actor’s tooling evolution from Quarian and PlugX toward the plugin-based QSC framework reflects a mature intrusion set focused on persistence, reconnaissance, credentialed lateral movement, and data access within strategically significant networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
20 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
36 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting targeted espionage intrusions against telecommunications/ISP organizations in South and West Asia using Quarian (Turian) for initial access/persistence, then deploying the QSC modular framework and GoClient backdoor for persistence, reconnaissance, remote command execution, credential abuse, lateral movement, and NTDS theft.
Assessed behind 2020 attacks on Middle Eastern and African governments using Quarian and PlugX, with initial access via Exchange exploitation (CVE-2020-0688) and ChinaChopper webshell deployment; historically targets high-profile Middle Eastern diplomatic entities.
Chinese-speaking activity cluster tied (in this text) to Hias, a fileless variant of HiKit, based on discovery of its persistence mechanism.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.