Turian
MITRE ATT&CK: S0647 View on attack.mitre.org
Aliases: Turian
- First seen
- 2021-01-01 00:00:00
- Malware type
- backdoor
- Family
- Malware family
- Operating systems
- windows, linux
- Related IoCs
- 1 (1 malicious)
- Last IoC activity
- 2026-08-21 04:15:28
- Profile updated
- 2026-07-07 13:00:06
Targeted industries: education-and-nonprofits government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:sy country_code:us
Context
Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
Recent IoC activity
1 malicious indicator in Maltiverse are attributed to Turian (S0647). The 1 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| file sample | 2026-08-21_8de677b2c53d4ea1eaa0333a80ef590e_elex_wannacry | 2026-08-21 | 1 |
Detection coverage
- 2 YARA rules
- 399 Sigma rules
Malware & tools used
- Unix Shell (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Screen Capture (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Archive via Utility (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Python (attack-pattern)
- Local Data Staging (attack-pattern)
- Junk Data (attack-pattern)
- Web Protocols (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Windows Command Shell (attack-pattern)
- System Information Discovery (attack-pattern)
- Masquerade Task or Service (attack-pattern)
- Peripheral Device Discovery (attack-pattern)
Used by threat actors
- BackdoorDiplomacy (threat-actor)
Detection rules
- DITEKSHEN_MALWARE_Win_Turian (yara-rule)
- MALPEDIA_Win_Turian_Auto (yara-rule)
Reports & references
- ESET — Backdoordiplomacy Upgrading Quarian Turian (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Turian (report)
- Palo Alto Unit 42 — Playful Taurus (report)
- fortinet.com — Analysis Of Follina Zero Day (report)
- MITRE ATT&CK — S0647 (report)