Kaspersky reported that the WhiteBear espionage campaign used the Gazer backdoor, a modular malware platform associated with long-term covert operations. According to MITRE ATT&CK, Gazer communicates with command-and-control servers over HTTP and protects parts of its traffic and stored data with custom encryption based on 3DES and RSA, indicating a design focused on resilient and concealed remote access.
The malware supports multiple persistence and evasion methods, including Start Menu shortcut creation or modification, Winlogon Shell registry changes, scheduled tasks, and screensaver-based execution. MITRE also documents process injection, thread execution hijacking, file download capability, configuration storage in alternate data streams, and stealth measures such as mutex use, file deletion, fake compilation timestamps in early variants, and code signing with valid certificates, underscoring the campaign's emphasis on maintaining access while avoiding detection.

Pull IOCs and campaign context straight into your stack.
2 events from the most recent confirmed update back to the earliest known activity.
Securelist published research titled "Introducing WhiteBear," which introduced the WhiteBear platform and its Gazer malware component. The reporting described Gazer's capabilities and linked it to the broader threat activity.
MITRE ATT&CK published a software entry for Gazer (S0168), documenting its command-and-control, persistence, encryption, injection, and stealth behaviors and mapping them to ATT&CK techniques.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.