Turian is a Windows remote access trojan and espionage backdoor associated with the China-linked threat actor BackdoorDiplomacy, also tracked as Playful Taurus. It has been used in operations targeting diplomatic entities and telecommunications companies in Africa and the Middle East.
Turian supports file operations, shell-command execution, process manipulation, and screenshot capture. It retrieves usernames and internal host IP addresses, discovers removable media, and collects files from connected storage. Collected files can be staged locally and packaged into password-protected archives using WinRAR before exfiltration. Persistence is established through Windows Registry autorun entries.
Turian obfuscates command-and-control addresses using XOR encryption and uses communications designed to resemble SSL traffic. Updated variants use Windows SSPI for secure communications, and some samples are protected with VMProtect. Its network-encryption setup can incorporate pseudorandom characters. A Turian variant has been deployed through a malicious Microsoft Word document exploiting the Microsoft Support Diagnostic Tool vulnerability CVE-2022-30190, also known as Follina.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This issue is referred to as “Follina’ and has a CVE assignment of CVE-2022-30190... a new unpatched vulnerability in Windows. A successful attack results in a remote, unauthenticated attacker taking control of an affected system. | This executable (SHA256: 4DDA59B51D51F18C9071EB07A730AC4548E36E0D14DBF00E886FC155E705EEEF) is a variant of Turian, which was analyzed by ESET almost a year ago.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A RAT used by BackdoorDiplomacy that supports file operations, shell-command execution and process manipulation, with C2 communications masquerading as SSL traffic. Its loading shellcode shares an RC4 key and LZNT1 decompression with RainyDay and early MetaRAT samples. The analyzed sample uses control-flow flattening. It is a comparison family, not confirmed malware deployed in this campaign, and BackdoorDiplomacy's involvement is not established.
Backdoor assessed to be used exclusively by BackdoorDiplomacy; overlaps with the described PlugX variant in tooling/implementation (e.g., DLL side-loading and similar encryption/decryption approach).
A Playful Taurus (APT15/KeChang) backdoor used for cyber-espionage. The analyzed variants are VMProtect-packed and use an updated C2 decryption routine and a modified network protocol leveraging Windows SSPI (InitSecurityInterfaceA/AcquireCredentialsHandleA/InitializeSecurityContextA) to perform an SSL/TLS-style handshake. It supports updating C2 configuration, executing commands, and spawning reverse shells; traffic is encrypted via SSPI EncryptMessage/DecryptMessage and additionally XORed with 0x56.
Backdoor that can retrieve usernames from compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.