Tunnus, also publicly reported as QUIETCANARY, is a lightweight .NET backdoor associated with the Turla espionage ecosystem. It has been linked to operations attributed to UNC4210/Turla, including activity targeting a Ukrainian organization, where it appeared as a later-stage payload following earlier compromise and victim profiling. Tunnus is designed for interactive post-compromise control of infected Windows systems, supporting command execution and file operations, and returning results to command-and-control infrastructure. Reported behavior includes executing processes in hidden windows to reduce user visibility, querying the Windows Registry for host information, and Base64-encoding command-and-control communications. In observed intrusions, operators used the malware after selective staging to interact with the victim environment and then compress, stage, and exfiltrate collected data. Its role, tradecraft, and association with Turla indicate use in targeted espionage operations against government, diplomatic, and related high-value entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"QUIETCANARY is a lightweight .NET backdoor also publicly reported as 'Tunnus'..."
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“communications… are RC4 encrypted and Base64 encoded over HTTPS.”
The content repeatedly describes malware and threat actors decoding, decrypting, deobfuscating, or unpacking payloads, strings, configuration data, commands, and C2 responses prior to execution or use.
Agent Tesla has used ProcessWindowStyle.Hidden to hide windows. APT-C-36 has set the ShowWindow property of the Win32_ProcessStartup object to zero to hide PowerShell execution. APT19 used -W Hidden to conceal PowerShell windows by setting the WindowStyle parameter to hidden.
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors using commands and APIs such as ipconfig /all, ifconfig, arp -a, route print, nbtstat, netsh, GetAdaptersInfo, and GetIpNetTable to gather IP addresses, MAC addresses, DNS, DHCP, gateways, routing tables, ARP cache, proxy settings, domains, and network adapter/interface details.
The content repeatedly describes threat actors and malware using HTTP and HTTPS for command and control, such as: "Sandworm Team used BlackEnergy to communicate between compromised hosts and their command-and-control servers via HTTP post requests."
“…downloaded and executed a WinRAR Self-Extracting Archive (WinRAR SFX) containing KOPILUWAK…” and “…downloaded and executed QUIETCANARY.”
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor malware capable of executing processes in hidden windows.
.NET-based backdoor capable of executing commands and file operations, communicating with C2 via compromised WordPress sites.
Malware that can Base64-encode command-and-control communications.
Malware that can Base64-encode command-and-control communications.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.