Quarian is a little-known Windows backdoor associated with Chinese-speaking cyberespionage activity and linked in multiple investigations to the CloudComputating cluster, also known as BackdoorDiplomacy or Faking Dragon. It has been observed in long-running intrusions against government, diplomatic, telecommunications, and internet service provider targets, including operations affecting Middle Eastern, African, South Asian, and West Asian organizations. Reporting also documents its use in attacks against a Southeast Asian government environment through DLL sideloading chains resembling known Quarian deployment tradecraft. Earlier public discussion additionally cited Quarian as malware that Turla allegedly deployed as a false flag during an incident in order to misdirect attribution toward China, but that episode reflects deceptive reuse rather than Quarian’s primary operator set.
Quarian is used to establish persistent remote access on compromised Windows systems and to support follow-on espionage activity. Documented deployments include DLL sideloading through legitimate executables and service abuse to load malicious DLLs. In later campaigns, Quarian version 3, also referred to as Turian, served as an access platform for deploying the modular QSC in-memory framework and additional tooling such as the GoClient backdoor. Through this access, operators conducted host and domain reconnaissance, identified domain controllers and file servers, executed commands, manipulated files, and enabled broader post-compromise operations including credential theft, lateral movement, and data collection. Associated activity has included use of stolen administrative credentials, remote execution, and theft of directory database material from domain controllers.
Operational patterns around Quarian are consistent with long-term espionage objectives rather than disruptive or financially motivated crime. Observed victimology and follow-on collection indicate interest in sensitive political, military, technical, and infrastructure information. Quarian has also been deployed alongside other Chinese espionage tooling, including PlugX and the QSC framework, reinforcing its role as a backdoor used to maintain footholds and stage additional malware in targeted intrusions.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
In one case, we could see that this variant was deployed following exploitation of the CVE-2020-0688 vulnerability on the network of a government entity. This vulnerability, which was publicly reported in February 2020, allows an authenticated user to run commands as SYSTEM on a Microsoft Exchange server. | Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.
5 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
rather they installed a somewhat rare, already compiled piece of Chinese malware by the name of Quarian.
Sophos MDR hunters observed the same sideloading chains described in the BitDefender report to deploy a Merlin C2 Agent and a suspected loader for the Quarian backdoor.
Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.
Our investigation found that the target machines had been infected with the Quarian backdoor version 3 (aka Turian) since 2022, and the same attackers had used this access to deploy the QSC framework starting on October 10, 2023.
Quarian is a little-known malicious program... we noticed a new variant that was used during several attacks on Middle Eastern and African governments during 2020.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
The Command Shell module launches % windir % \ system32 \ cmd . exe as a shell using the CreateProcess API, and data is written to and read from the shell using pipes.
The belief is that the actors recognized researcher systems in their logs and instead of serving the normal second-stage binary, they instead provided a ‘fake’, unrelated piece of malware to cause confusion.
12 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A backdoor referenced as the suspected intended payload of a sideloading chain, though execution was prevented before confirmation.
A backdoor referenced as the payload targeted for deployment via a suspected loader in a sideloading chain.
Backdoor referenced as a payload in suspected loader/sideloading chains (payload deleted before execution in this case).
A backdoor used as the initial access and deployment mechanism for QSC and GoClient. It was used to launch command shells, execute batch scripts, copy payloads, and run additional tools during post-compromise activity.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.