Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
MalwareUsed by 4 actorsExploits 1 CVE

Quarian

Quarian is a little-known backdoor malware family, including a version 3 variant also referred to as Turian. Reporting in the provided content links Quarian to Chinese-speaking espionage activity and assesses with medium to high confidence that some Quarian/PlugX operations were conducted by the CloudComputating group, also known as BackdoorDiplomacy or Faking Dragon. Quarian was observed in attacks against Middle Eastern and African governments in 2020, and later in a long-running intrusion affecting an ISP in West Asia where victim machines had been infected with Quarian v3 since 2022. In that case, attackers used existing Quarian access to deploy the modular in-memory QSC framework beginning on October 10, 2023, and also deployed the GoClient Golang backdoor. Quarian has been delivered via DLL sideloading chains, including abuse of legitimate executables such as mobpopup.exe renamed to winsecunicity.exe to sideload pc2msupp.dll, and Sophos observed similar sideloading chains associated with suspected Quarian loader deployment. Another reported infection chain involved exploitation of Microsoft Exchange CVE-2020-0688 followed by a ChinaChopper web shell to deploy Quarian and PlugX. Quarian was also observed modifying Windows services such as swprv and rasauto so ServiceDll values pointed to QSC loader DLLs including swprr.dll and rasautosvc.dll. A reported Quarian sample located at C:\Windows\SysWOW64\appmgmt.dll had MD5 97b0a8e8d125e71d3d1dd8e241d70c5b and was configured to use proxy.oracleapps.org, infrastructure previously linked to BackdoorDiplomacy. The malware is associated in the content with government and telecom/ISP targeting in the Middle East, Africa, and West Asia, and with post-compromise activity including persistence, loader deployment, and enabling follow-on espionage tooling.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

1 CVES
CVE-2020-0688Microsoft Exchange Memory Corruption VulnerabilityExploited in the wild

In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.

via securelistsecurelist.com
THREAT ACTORS

Groups observed using it

4 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
BackdoorDiplomacy

Sophos MDR hunters observed the same sideloading chains described in the BitDefender report to deploy a Merlin C2 Agent and a suspected loader for the Quarian backdoor.

via sophos threat researchsophos.com
CloudComputating

Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.

via securelistsecurelist.com
Faking Dragon

Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.

via securelistsecurelist.com
Icefog

Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.

via securelistsecurelist.com
MITRE ATT&CK

Techniques & procedures

6 distinct techniques documented for this family, organized by ATT&CK tactic.

Initial Access

1 technique
T1190Exploit Public-Facing ApplicationEvidence1

"...deployed following exploitation of the CVE-2020-0688 vulnerability... on a Microsoft Exchange server."

Execution

3 techniques
T1059.003Windows Command ShellEvidence1

The Command Shell module launches % windir % \ system32 \ cmd . exe as a shell using the CreateProcess API, and data is written to and read from the shell using pipes.

T1569.002Service ExecutionEvidence1

net stop swprv ... sc config swprv start = auto ... net start swprv

T1574.011Services Registry Permissions WeaknessEvidence1

reg add HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ services \ swprv \ Parameters / v ServiceDll / t REG_EXPAND_SZ / d c : \ windows \ system32 \ swprr . dll / f

Persistence

1 technique
T1505.003Web ShellEvidence1

"...was hosting the ChinaChopper webshell, which was used to obtain, and later launch, the Quarian and PlugX backdoors."

Stealth

1 technique
T1574.011Services Registry Permissions WeaknessEvidence1

reg add HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ services \ swprv \ Parameters / v ServiceDll / t REG_EXPAND_SZ / d c : \ windows \ system32 \ swprr . dll / f

Command and Control

1 technique
T1105Ingress Tool TransferEvidence1

In addition to the QSC framework, the attackers also deployed a new backdoor written in Golang, which we have named “GoClient”.

INDICATORS OF COMPROMISE

IOCs tracked for this family

12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
8 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
4 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
domain●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
hash.md5●●●●●●●●●●●●View more in app5 years ago
domain●●●●●●●●●●●●View more in app5 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching12

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution4

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities1

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping6

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.