Turian

Malware updated a month ago (2024-11-29T13:51:41.850Z)
Download STIX
Preview STIX
Turian, also known as Quarian backdoor version 3, is a potent malware that has been used by attackers to exploit target machines. First compiled on April 28, 2022, Turian was found to have infected target systems since 2022, allowing the same attackers to deploy the QSC framework and GoClient backdoor from October 10, 2023. This malware is associated with a specific domain and can be identified through its unique SHA-256 sample. A key feature of Turian and Quarian backdoors is their distinct network protocol, particularly during the initial key exchange. In January, Turian was utilized in a significant cyberattack against four Iranian government organizations, including Iran's Ministry of Foreign Affairs. The attackers, known as Flea, leveraged a new version of the Turian malware to compromise these networks. This incident highlights the evolving nature of the Turian malware and its potential for causing extensive damage when deployed against sensitive targets. Protection against Turian involves the use of Behavioral Threat Protection and the newly released in-memory shellcode protection included in Cortex 3.5. These measures are designed to prevent the execution of Turian malware, thereby mitigating the risk of data theft, operational disruption, and other potential harms caused by such malicious software. Further information about Turian can be accessed via the link: https://unit42.paloaltonetworks.com/playful-taurus/#post-126622-_9g8tqsio8dql.
Description last updated: 2024-11-08T15:16:01.400Z
What's your take? (Question 1 of 1)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Backdoor
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the Turian Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more