Cisco Talos published IOCs ↗
- Evidence class
- provider reported
- Source family label
- Turian - S0647
- Source confidence
- Not reported
- Observed
- 2025-09-28 19:50 UTC
- Retrieved
- 2026-10-08 06:17 UTC
Name of ATT&CK software | [Turian](https://attack.mitre.org/software/S0647) is a backdoor that has been used by [BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) to target Ministries of Foreign Affairs, telecommunication companies, and charities in Africa, Europe, the Middle East, and Asia. First reported in 2021, [Turian](https://attack.mitre.org/software/S0647) is likely related to Quar
2025/09/how-rainyday-turian-and-a-new-plugx-variant-abuse-dll-search-order-hijacking.jsonNetwork addresses are displayed in defanged form.
No file hashes or network indicators were published in this record.