WhiteAtlas

Description

(Kaspersky) The White Atlas framework often utilized a small Javascript script to execute the malware dropper payload after it was decrypted by the VBA macro code, then to delete the dropper afterwards. A much more advanced and highly obfuscated Javascript script was utilized in White Atlas samples that dropped a Firefox extension backdoor developed by Turla, but again the script was responsible for the simple tasks of writing out the extension.json configuration file for the extension and deleting itself for cleanup purposes.

Names

Name
WhiteAtlas

Category

Malware

Type

  • Dropper

Information

Other Information

Uuid

c3f21a5b-b2fa-4c71-a4bc-8295b78e10cc

Last Card Change

2020-04-20