PULSE NAME
Introducing WhiteBear
WHITE Turla Group AlienVault 2017-08-30 Modified: 2017-08-30
9
IOCs
LOW VOLUME
As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we called WhiteBear. Much of the contents of that report are reproduced here. WhiteBear is a parallel project or second stage of the Skipper Turla cluster of activity documented in another private intelligence report “Skipper Turla – the White Atlas framework” from mid-2016. Like previous Turla activity, WhiteBear leverages compromised websites and hijacked satellite connections for command and control (C2) infrastructure.
Indicators of Compromise (1 / 9 total)
All URL domain FileHash-MD5 IPv4
TYPEINDICATORDESCRIPTIONCREATED
URL http://soligro.com/wp-includes/pomo/db.php 2017-08-30