Turian — Malware Profile
Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
MITRE ATT&CK techniques (18)
- T1001.001 Junk Data
- T1016 System Network Configuration Discovery
- T1027 Obfuscated Files or Information
- T1033 System Owner/User Discovery
- T1036.004 Masquerade Task or Service
- T1059.003 Windows Command Shell
- T1059.004 Unix Shell
- T1059.006 Python
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1113 Screen Capture
- T1120 Peripheral Device Discovery
- T1140 Deobfuscate/Decode Files or Information
- T1547.001 Registry Run Keys / Startup Folder
- T1560.001 Archive via Utility