Malware.View on attack.mitre.org
Turian is a backdoor that has been used by BackdoorDiplomacy to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, Turian is likely related to Quarian, an older backdoor that was last observed being used in 2013 against diplomatic targets in Syria and the United States.
| Technique | Procedure example |
|---|---|
| T1001.001 Junk Data |
Turian can insert pseudo-random characters into its network encryption setup. |
| T1016 System Network Configuration Discovery |
Turian can retrieve the internal IP address of a compromised host. |
| T1027 Obfuscated Files or Information |
Turian can use VMProtect for obfuscation. |
| T1033 System Owner/User Discovery |
Turian can retrieve usernames. |
| T1036.004 Masquerade Task or Service |
Turian can disguise as a legitimate service to blend into normal operations. |
| T1059.003 Windows Command Shell |
Turian can create a remote shell and execute commands using cmd. |
| T1059.004 Unix Shell |
Turian has the ability to use |
| T1059.006 Python |
Turian has the ability to use Python to spawn a Unix shell. |
| T1071.001 Web Protocols |
Turian has the ability to use HTTP for its C2. |
| T1074.001 Local Data Staging |
Turian can store copied files in a specific directory prior to exfiltration. |
| T1082 System Information Discovery |
Turian can retrieve system information including OS version, memory usage, local hostname, and system adapter information. |
| T1083 File and Directory Discovery |
Turian can search for specific files and list directories. |
| T1105 Ingress Tool Transfer |
Turian can download additional files and tools from its C2. |
| T1113 Screen Capture |
Turian has the ability to take screenshots. |
| T1120 Peripheral Device Discovery |
Turian can scan for removable media to collect data. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.