Turian

MITRE ATT&CK: S0647 View on attack.mitre.org

Aliases: Turian

First seen
2021-01-01 00:00:00
Malware type
backdoor
Family
Malware family
Operating systems
windows, linux
Related IoCs
1 (1 malicious)
Last IoC activity
2026-08-21 04:15:28
Profile updated
2026-07-07 13:00:06

Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:sy country_code:us

Context

Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.

Recent IoC activity

1 malicious indicator in Maltiverse are attributed to Turian (S0647). The 1 most recently updated:

TypeIndicatorUpdatedSources
file sample 2026-08-21_8de677b2c53d4ea1eaa0333a80ef590e_elex_wannacry 2026-08-21 1

Detection coverage

  • 2 YARA rules
  • 399 Sigma rules

Malware & tools used

  • Unix Shell (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Obfuscated Files or Information (attack-pattern)
  • Screen Capture (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Archive via Utility (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Python (attack-pattern)
  • Local Data Staging (attack-pattern)
  • Junk Data (attack-pattern)
  • Web Protocols (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Masquerade Task or Service (attack-pattern)
  • Peripheral Device Discovery (attack-pattern)

Used by threat actors

Detection rules

  • DITEKSHEN_MALWARE_Win_Turian (yara-rule)
  • MALPEDIA_Win_Turian_Auto (yara-rule)

Reports & references

  • ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Turian (report)
  • Palo Alto Unit 42 — Playful Taurus (report)
  • fortinet.com — Analysis Of Follina Zero Day (report)
  • MITRE ATT&CK — S0647 (report)

External references