BackdoorDiplomacy
Reports per quarter
Techniques seen in the last two years
- T1091 1 report reports only
- T1190 1 report in ATT&CK
- T1195 1 report reports only
- T1557 1 report reports only
- T1566.001 1 report reports only
- T1566.002 1 report reports only
- T1566.003 1 report reports only
- T1659 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4404 KEV
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
- CVE-2015-1130 KEV
- CVE-2015-1635 KEV
- CVE-2015-2051 KEV
Show all 38 CVEs Show fewer
- CVE-2015-7248
- CVE-2017-11882 KEV ransomware
- CVE-2017-5638 KEV ransomware
- CVE-2018-10562 KEV ransomware
- CVE-2018-8440 KEV ransomware
- CVE-2019-11510 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2020-5902 KEV ransomware
- CVE-2021-26605
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-27065 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2022-27926 KEV
- CVE-2023-23397 KEV
- CVE-2023-36884 KEV ransomware
- CVE-2023-38831 KEV ransomware
- CVE-2024-11182 KEV
- CVE-2024-23204
- CVE-2024-49039 KEV ransomware
- CVE-2024-9680 KEV ransomware
- CVE-2025-55182 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CHINACHOPPER (Malware Family)
-
Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ke3chang, Vixen Panda, APT 15, GREF, Playful Dragon
-
Chinese Playful Taurus Activity in Iran
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese Playful Taurus Activity in Iran
-
Deep Dive Into a BackdoorDiplomacy Attack – A Study of an Attacker’s Toolkit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Dive Into a BackdoorDiplomacy Attack – A Study of an Attacker’s Toolkit
Show all 15 reports Show fewer
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor eset_threat_report_t22021
-
BackdoorDiplomacy- Upgrading from Quarian to Turian
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor BackdoorDiplomacy- Upgrading from Quarian to Turian
Newest first. Details opens the report in Explore.