Turian

S0647

Malware.View on attack.mitre.org

About this malware

Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1001.001
Junk Data

Turian can insert pseudo-random characters into its network encryption setup.

T1016
System Network Configuration Discovery

Turian can retrieve the internal IP address of a compromised host.

T1027
Obfuscated Files or Information

Turian can use VMProtect for obfuscation.

T1033
System Owner/User Discovery

Turian can retrieve usernames.

T1036.004
Masquerade Task or Service

Turian can disguise as a legitimate service to blend into normal operations.

T1059.003
Windows Command Shell

Turian can create a remote shell and execute commands using cmd.

T1059.004
Unix Shell

Turian has the ability to use /bin/sh to execute commands.

T1059.006
Python

Turian has the ability to use Python to spawn a Unix shell.

T1071.001
Web Protocols

Turian has the ability to use HTTP for its C2.

T1074.001
Local Data Staging

Turian can store copied files in a specific directory prior to exfiltration.

T1082
System Information Discovery

Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information.

T1083
File and Directory Discovery

Turian can search for specific files and list directories.

T1105
Ingress Tool Transfer

Turian can download additional files and tools from its C2.

T1113
Screen Capture

Turian has the ability to take screenshots.

T1120
Peripheral Device Discovery

Turian can scan for removable media to collect data.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References1

  1. ESET BackdoorDiplomacy Jun 2021 Open source
    Adam Burgher. (2021, June 10). BackdoorDiplomacy: Upgrading from Quarian to Turian. Retrieved September 1, 2021

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.