WhiteBear

Threat Actor updated 5 months ago (2024-05-05T01:17:44.329Z)
Download STIX
Preview STIX
WhiteBear is a threat actor that has been associated with the Turla group, also known as Snake, Venomous Bear, Uroburos, and WhiteBear. This association was established through strong links identified between a Crutch dropper from 2016 and Gazer, a second-stage backdoor used by Turla in 2016-2017. WhiteBear's activities included scripting spearphish attachments, following up on initial WhiteAtlas scripting development and deployment efforts, and sharing infrastructure with KopiLuwak while deploying unusual .js scripting. The encryption implemented in the WhiteBear orchestrator is notably complex, highlighting the sophistication of this threat actor. From a targeting perspective, there was a close alignment between the activities of WhiteBear and KopiLuwak, with shared known compromised infrastructure such as soligro[.]com. This domain was used in another Turla operation (KopiLuwak) and served as the C2 server for the WhiteBear transport library. The targets of WhiteBear over a couple of years were related to government foreign affairs, international organizations, and later, defense organizations. Its activities stretched across the globe, indicating a broad scope of operations. Despite its prolific and longstanding nature, WhiteBear activity reliant on this toolset seemed to have diminished in June 2017. However, it is important to note that the WhiteBear C2 servers are consistent with long-standing Turla infrastructure management practices, meaning the backdoors callback to a mix of compromised servers and hijacked destination satellite IP hosts. As such, Turla remains one of the most advanced and researched Advanced Persistent Threats (APTs), with the potential for continued or resurgent activity.
Description last updated: 2024-05-05T00:42:02.822Z
Aliases We are not currently tracking any aliases
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Source Document References
Information about the WhiteBear Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more