ESET, a global leader in the cybersecurity market, has discovered BackdoorDiplomacy, a new APT group that primarily targets ministries of Foreign Affairs in the Middle East and Africa and, less frequently, telecommunications companies.
Attacks typically begin by exploiting vulnerable internet-exposed applications on web servers to install a custom backdoor that ESET has named Turian. BackdoorDiplomacy can detect removable media, presumably USB flash drives, and copy their contents to the main drive's recycle bin. The research was exclusively previewed at this week's annual ESET World conference.
"BackdoorDiplomacy shares tactics, techniques and procedures with other Asia-based groups. Turian likely represents an evolution of Quarian, the backdoor last observed in use in 2013 against diplomatic targets in Syria and the United States," he explained Jean-Ian Boutin, Head of Threat Research di ESET, who worked on this investigation with Adam Burgher, Senior Threat Intelligence Analyst di ESET. Turian's network encryption protocol is nearly identical to that used by Whitebird, a backdoor operated by Calypso, another Asia-based group. Whitebird was deployed within diplomatic organizations in Kazakhstan and Kyrgyzstan in the same period as BackdoorDiplomacy (2017-2020).
BackdoorDiplomacy victims have been identified in the Ministries of Foreign Affairs of several African countries, as well as in Europe, the Middle East and Asia. Other targets include telecommunications companies in Africa, and at least one charity in the Middle East. In each case, operators employed similar tactics, techniques and procedures (TTPs), but modified the tools used, even within nearby geographic areas, probably to make monitoring the group more difficult.
BackdoorDiplomacy is also a cross-platform group that targets both Windows and Linux systems. It targets servers with ports exposed to the internet, which it attacks, most likely, by exploiting file-upload security flaws or unpatched vulnerabilities – in one case leading to a webshell, called China Chopper, used by various groups. The hackers attempted to disguise their backdoor droppers and evade detection.
A subset of victims were hit with data collection executables designed to search removable media (most likely USB flash drives). The mount routinely scans for these drives and, after detecting the insertion of removable media, attempts to copy all files to a password-protected archive. BackdoorDiplomacy is capable of stealing victim's system information, taking screenshots, and writing, moving, or deleting files.
For more technical details on BackdoorDiplomacy, see the blog post “BackdoorDiplomacy: Aggiornamento da Quarian a Turian" his WeLiveSecurity. All the latest news can be found following ESET Research su Twitter.






