Skip to main content

Russian APTs And WhiteBear Related Activity

The Russian APT group Turla has been active against defence, diplomatic and political targets, using a toolset known as WhiteBear .
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

The Russian APT group Turla has been active against defence, diplomatic and political targets, using a toolset known as WhiteBear .

Affected platforms

The following platforms are known to be affected:

Threat details

The majority of victims of WhiteBear are located in Europe; with the main focus being on South Eastern Europe and former Warsaw pact members. The targeting has the hallmarks of previous Turla activity and includes the following characteristics:
• Targets embassies and government ministries.
• Uses spear phishing to deliver a first stage backdoor.
• A second stage backdoor is put in place
• The second stage backdoor receives encrypted instructions via a C&C server by means of a compromised website.

WhiteBear is extremely sophisticated and is believed to change strings within its code. It randomises markers an also wipes files securely in order to avoid detection.

Turla have traditionally targeted diplomatic, government, military, nuclear research and other academic organisations in the USA, Europe and former Soviet sphere of influence nations. Victims are infected via spear phishing emails and watering-hole attacks, which deliver Wipbot or Tavdig malware and then delivers Turla (aka Uroburos, Carbon, Snake) to the victim.

The rootkit hides and creates a hidden and encrypted file system to store data and tools, which are then used to access systems, store information and steal passwords. The actors are believed to have utilised a number of command and control servers worldwide during their campaigns.


Remediation steps

Type Step
• Don’t open any mail attachments you’re unsure of even if you trust the sender.
• Ensure staff are properly trained on common phishing techniques.
• Some settings may be available on certain email services that disable automatic execution of a remote resource.

Last edited: 17 February 2020 11:38 am