WhiteAtlas
Description
(Kaspersky) The White Atlas framework often utilized a small Javascript script to execute the malware dropper payload after it was decrypted by the VBA macro code, then to delete the dropper afterwards. A much more advanced and highly obfuscated Javascript script was utilized in White Atlas samples that dropped a Firefox extension backdoor developed by Turla, but again the script was responsible for the simple tasks of writing out the extension.json configuration file for the extension and deleting itself for cleanup purposes.
Names
Name |
---|
WhiteAtlas |
Category
Malware
Type
- Dropper
Information
Other Information
Uuid
c3f21a5b-b2fa-4c71-a4bc-8295b78e10cc
Last Card Change
2020-04-20