AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← Catalog
REFERENCEPUBLIC INTELLIGENCE

Turian - S0647

Name of ATT&CK software | [Turian](https://attack.mitre.org/software/S0647) is a backdoor that has been used by [BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, [Turian](https://attack.mitre.org/software/S0647) is likely related to Quar

Reference details

Primary displayed family label
Turian - S0647
Source context
2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.json
First reported
2025-09-28 19:50 UTC
Last reported
2025-09-28 19:50 UTC
Catalog updated
2026-10-08 06:17 UTC

Source family labels

Turian - S0647

Tags

misp:galaxy-name="Malware"misp:galaxy-type="mitre-malware"misp-galaxy:mitre-malware="Turian - S0647"

Published indicators

Network addresses are displayed in defanged form.

No file hashes or network indicators were published in this record.

Source observations

Cisco Talos published IOCs ↗

Evidence class
provider reported
Source family label
Turian - S0647
Source confidence
Not reported
Observed
2025-09-28 19:50 UTC
Retrieved
2026-10-08 06:17 UTC

Research references