Turian, also known as Quarian and Whitebird, is a Windows backdoor associated with the China-linked espionage group Playful Taurus, also tracked as APT15, KeChang, NICKEL, Vixen Panda, and BackdoorDiplomacy. It has been assessed as a tool used exclusively by that actor set and has remained under active development since it was publicly identified in 2021. Operations involving Turian have focused on cyber-espionage, including targeting government and diplomatic entities, with notable activity affecting organizations in the Middle East.
Turian supports a range of post-compromise collection and host profiling functions. Reported capabilities include taking screenshots, retrieving the internal IP address of an infected host, collecting usernames, and scanning removable media to identify and gather files of interest. It can stage copied files locally prior to theft and can create password-protected archives using WinRAR to prepare collected data for exfiltration. Samples have also used XOR-based decryption to recover embedded command-and-control configuration data, and newer variants have been observed using updated encrypted communications mechanisms.
For persistence, Turian can establish autorun execution through Windows Registry Run keys. Variants have also shown tradecraft consistent with local staging of collected material before transmission to operator-controlled infrastructure. The malware is best characterized as an espionage backdoor rather than commodity crimeware, with functionality oriented toward surveillance, collection, and sustained access on compromised Windows systems. Turian has also been observed in exploitation chains leveraging CVE-2022-30190 (Follina), where malicious Microsoft Office documents triggered code execution and led to deployment of a Turian variant.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
This issue is referred to as “Follina’ and has a CVE assignment of CVE-2022-30190... a new unpatched vulnerability in Windows. A successful attack results in a remote, unauthenticated attacker taking control of an affected system. | This executable (SHA256: 4DDA59B51D51F18C9071EB07A730AC4548E36E0D14DBF00E886FC155E705EEEF) is a variant of Turian, which was analyzed by ESET almost a year ago.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Turian (aka Quarian or Whitebird), on the other hand, is assessed to be a backdoor exclusively employed in cyber attacks targeting the Middle East...
24 distinct techniques documented for this family, organized by ATT&CK tactic.
MSDT was then invoked using character and Base64 encoding to obfuscate the actual command.
This document then invoked msdt.exe, followed by several PowerShell commands.
The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
a malicious Microsoft Word document submitted from Belarus that leverages remote templates to execute a PowerShell payload using the "ms-msdt" MSProtocol URI scheme
threat actors are now using CVE-2022-30190 exploits to execute malicious code via the MSDT protocol when targets open or preview Word documents delivered in ZIP archives
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
MSDT was then invoked using character and Base64 encoding to obfuscate the actual command.
APT41 used VMProtected binaries in multiple intrusions. BackdoorDiplomacy has obfuscated tools and malware it uses with VMProtect. KillDisk uses VMProtect to make reverse engineering the malware more difficult. Turian can use VMProtect for obfuscation.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
The content repeatedly describes malware and threat actors collecting the username, identifying the current user, enumerating logged-on users, or running commands such as whoami, query user, and quser to determine user context on compromised systems.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
The content is a long ATT&CK-style listing of groups and malware that can 'list files and directories,' 'search for files,' 'enumerate drives,' 'gather file metadata,' or 'browse file systems' on compromised hosts.
ADVSTORESHELL can list connected devices. APT28 uses a module to receive a notification every time a USB mass storage device is inserted into a victim. APT37 has a Bluetooth device harvester, which uses Windows Bluetooth APIs to find information on connected Bluetooth devices.
this variant uses the same headers to connect to the C2 server
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
7 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
22 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor assessed to be used exclusively by BackdoorDiplomacy; overlaps with the described PlugX variant in tooling/implementation (e.g., DLL side-loading and similar encryption/decryption approach).
A Playful Taurus (APT15/KeChang) backdoor used for cyber-espionage. The analyzed variants are VMProtect-packed and use an updated C2 decryption routine and a modified network protocol leveraging Windows SSPI (InitSecurityInterfaceA/AcquireCredentialsHandleA/InitializeSecurityContextA) to perform an SSL/TLS-style handshake. It supports updating C2 configuration, executing commands, and spawning reverse shells; traffic is encrypted via SSPI EncryptMessage/DecryptMessage and additionally XORed with 0x56.
Backdoor that can retrieve usernames from compromised systems.
A backdoor payload delivered via exploitation of CVE-2022-30190. The sample uses a one-byte XOR key (0xA9) for decryption, checks the infected host's domain role, connects to a C2 server using characteristic headers, and creates tmp.bat to set RUN registry keys for persistence.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.