Diplomatic & Foreign Affairs — Cyber Threat Activity
Diplomatic and foreign affairs is the purest espionage sector in this dataset and holds no recorded incidents in our log at all, which is what a target class that never issues a breach notification looks like. The evidence is the actor graph: 37 groups carry a researched association with diplomatic targeting, including Turla, Mustang Panda, APT15, APT35, ZIRCONIUM, Storm-0558 and BackdoorDiplomacy, with 94 malware families linked through those actors. Foreign ministries, embassies, consulates and permanent missions are attacked because they hold negotiating positions, cables, visa and travel records and the private assessments a government makes of its counterparts, all of which are valuable before a decision is announced rather than after. ESET's analysis of Turla activity found the targeting concentrated on consulates and embassies across Eastern Europe and the former Soviet space, delivered through fake software installers that required no exploit at all, only a user who believed a plausible update prompt. Other operators have reached the same material by compromising cloud identity infrastructure and reading government mailboxes directly, which removes the need to touch the ministry's own network. Diplomatic missions are structurally hard to defend: they operate on foreign soil and foreign networks, rotate staff on posting cycles, and must remain contactable by outside parties by definition. The absence of incident volume on this page is a collection limit, not a finding. These associations come from published vendor and government research on each group rather than from incidents we have attributed ourselves.
- Recorded incidents: 0
- Incidents, trailing 180 days: 0
- Tracked threat actors: 38
- Malware families: 102
Threat actors targeting Diplomatic & Foreign Affairs
- APT35 researched targeting
- Mustang Panda researched targeting
- Storm-0558 researched targeting
- Turla researched targeting
- ZIRCONIUM researched targeting
- Actor240524 researched targeting
- APT15 researched targeting
- BackdoorDiplomacy researched targeting
- Careto researched targeting
- Cycldek researched targeting
- Earth Kitsune researched targeting
- Earth Krahang researched targeting
- Gallmaker researched targeting
- GhostNet researched targeting
- GhyamSarnegouni researched targeting
- GoldenJackal researched targeting
- Higaisa researched targeting
- I-Soon researched targeting
- Inception researched targeting
- IndigoZebra researched targeting
- InvisiMole researched targeting
- Molerats researched targeting
- MoustachedBouncer researched targeting
- Mysterious Elephant researched targeting
Malware used against Diplomatic & Foreign Affairs
Families used by the threat actors that target this sector, derived from actor tooling rather than observed in these incidents directly.
- Cobalt Strike Malware
- Impacket Tool
- Metasploit Tool
- Mimikatz Tool
- PlugX Malware
- PsExec Tool
- AdFind Tool
- China Chopper Malware
- Empire Tool
- gh0st RAT Malware
- Havoc Malware
- LaZagne Tool
Recent incidents
No incidents in this sector are recorded in our log. Our incident corpus is built from ransomware leak-site claims and public breach notifications, which do not cover espionage — for Diplomatic & Foreign Affairs the actor and malware graph above is the substantive record.
Coverage. 94.7% of incidents in our log carry a sector classification; the remainder name a victim we have not placed in an industry. Counts here are a floor, not a total, and are not comparable between sectors of different sizes.