Quarian is a Windows backdoor associated with cyberespionage operations by BackdoorDiplomacy, also tracked as CloudComputating and Faking Dragon. It provides remote command shells, command execution, file operations, and system discovery. Its variants include Turian, identified as Quarian version 3, and samples associated with the name Whitebird. Newer samples use Windows Schannel for genuine TLS-protected command-and-control communications and implement revised command identifiers.
Quarian has targeted government organizations in the Middle East and Africa and telecommunications organizations in the Middle East and West Asia. In a documented 2020 intrusion, attackers exploited Microsoft Exchange vulnerability CVE-2020-0688 and used a ChinaChopper web shell to deploy Quarian and PlugX. Deployment techniques include DLL side-loading through legitimate Windows executables, loaders that extract and execute shellcode, and VMProtect-packed executable variants. Quarian access has also been used to install additional malware: systems compromised with Turian since 2022 were subsequently used to deploy the modular QSC framework in October 2023.
Quarian is not exclusive to its principal associated operators. Turla deployed it during a documented 2012 intrusion and removed its own Wipbot implant, using unrelated Chinese malware to misdirect incident responders and complicate attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
rather they installed a somewhat rare, already compiled piece of Chinese malware by the name of Quarian.
Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.
Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.
Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The Command Shell module launches % windir % \ system32 \ cmd . exe as a shell using the CreateProcess API, and data is written to and read from the shell using pipes.
The belief is that the actors recognized researcher systems in their logs and instead of serving the normal second-stage binary, they instead provided a ‘fake’, unrelated piece of malware to cause confusion.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor referenced as the suspected intended payload of a sideloading chain, though execution was prevented before confirmation.
A backdoor referenced as the payload targeted for deployment via a suspected loader in a sideloading chain.
Backdoor referenced as a payload in suspected loader/sideloading chains (payload deleted before execution in this case).
Backdoor used from February 2022 in the Middle Eastern telecommunications espionage campaign most likely attributed to BackdoorDiplomacy. It was deployed alongside scanning and proxy/tunneling tools; its specific capabilities are not detailed.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.