Russian APTs And WhiteBear Related Activity
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Affected platforms
The following platforms are known to be affected:
Threat details
The majority of victims of WhiteBear are located in Europe; with the main focus being on South Eastern Europe and former Warsaw pact members. The targeting has the hallmarks of previous Turla activity and includes the following characteristics:
• Targets embassies and government ministries.
• Uses spear phishing to deliver a first stage backdoor.
• A second stage backdoor is put in place
• The second stage backdoor receives encrypted instructions via a C&C server by means of a compromised website.
WhiteBear is extremely sophisticated and is believed to change strings within its code. It randomises markers an also wipes files securely in order to avoid detection.
Turla have traditionally targeted diplomatic, government, military, nuclear research and other academic organisations in the USA, Europe and former Soviet sphere of influence nations. Victims are infected via spear phishing emails and watering-hole attacks, which deliver Wipbot or Tavdig malware and then delivers Turla (aka Uroburos, Carbon, Snake) to the victim.
The rootkit hides and creates a hidden and encrypted file system to store data and tools, which are then used to access systems, store information and steal passwords. The actors are believed to have utilised a number of command and control servers worldwide during their campaigns.
Remediation steps
Last edited: 17 February 2020 11:38 am