Turian
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 21/09/2021 17:21
- Modified
- 27/03/2026 01:03
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 22 attack patterns (mitre), 2 intrusion sets (apt), 4 countries, 17 indicators, 2 vulnerabilities (cve)
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (22)
-
T1113 usesScreen Capture MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1083 usesFile and Directory Discovery MITRE
-
Junk Data usesT1001.001 MITRE
-
T1120 usesPeripheral Device Discovery MITRE
-
T1059.004 usesUnix Shell MITRE
-
T1033 usesSystem Owner/User Discovery MITRE
-
T1001 usesData Obfuscation MITRE
-
T1547.001 usesRegistry Run Keys / Startup Folder MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1566 usesPhishing MITRE
Intrusion sets (APT) (2)
-
BackdoorDiplomacy usesThe MITRE Corporation Confidence 100
[BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) is a cyber espionage threat group that has been active since at least 2017. [BackdoorDiplomacy](https://attack.mitre.org/groups/G0135) has targeted Ministries of Foreign Affairs and telecommunication companies in Africa, Europe,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
TA413 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Countries (4)
-
India targets
-
Philippines targets
-
Russian Federation targets
-
Nepal targets
Indicators (17)
-
stix 100/100 Revoked
SLF:SCPT:OffRelOleObjectHttp.A
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelOleObjectHttp.A
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked
vad_contains_network_strings
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
http://212.138.130.8/analysis.htmlindicatesstix 100/100 Revoked· Valid until 20/07/2022 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelOleObjectHttp.A
· Valid until 06/09/2023 · Source: AlienVault
Vulnerabilities (CVE) (2)
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An …
- Published
- 14/06/2022
- Modified
- 27/05/2026
HTTP Protocol Stack Remote Code Execution Vulnerability
- Attack vector
- NETWORK
- Published
- 11/01/2022
- Modified
- 20/12/2025