Gazer, also known as WhiteBear, is a stealthy Windows backdoor associated with the Turla espionage group. It has been used since at least 2016 in targeted intrusions against governments, diplomats, embassies, consulates, and ministries, with reporting indicating a concentration of victims in Europe, particularly Southeastern Europe and former Soviet Union countries. Gazer is typically described as a second-stage implant in Turla operations, following initial compromise through spearphishing-delivered first-stage malware, and is designed for long-term covert access and information theft.
The malware communicates with command-and-control infrastructure over HTTP and protects parts of its communications and stored data with custom cryptography, including 3DES and RSA. It injects its communication module into an Internet-accessible process to blend command-and-control traffic with legitimate activity, and it also performs thread execution hijacking to run components inside remote processes. Reported tasking includes downloading files from operators.
Gazer supports multiple persistence mechanisms on Windows. These include creating or modifying Start menu shortcut files, creating scheduled tasks, altering the Winlogon Shell configuration, and abusing screensaver execution for logon or idle-time persistence. When normal registry-based storage is unavailable, it can store configuration data in NTFS alternate data streams. Additional stealth and anti-forensic features include use of a mutex to enforce a single running instance, deletion of files and persistence artifacts on command, secure wiping behavior, fake compilation timestamps in early versions, randomized markers, and code-string changes intended to hinder detection. Some versions were also signed with valid certificates to reduce suspicion.
The malware gathers host context including the current user’s security identifier. Overall, Gazer is a mature Turla backdoor built for covert persistence, defense evasion, and sustained post-compromise espionage on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This trick is used by Gazer software and Turla APT in the wild.
25 distinct techniques documented for this family, organized by ATT&CK tactic.
In that case, the following modifications are made in the Windows registry: HKCU\Software\Classes\CLSID\{49CBB1C7-97D1-485A-9EC1-A26065633066} ...
Gazer can establish persistence through the system screensaver by configuring it to execute the malware.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Gazer injects its communication module into an Internet accessible process through which it performs C2.
Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.
Gazer can establish persistence through the system screensaver by configuring it to execute the malware.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
Gazer makes extra efforts to evade detection by changing strings within its code, randomizing markers, and wiping files securely.
Gazer logs its actions into files that are encrypted with 3DES. It also uses RSA to encrypt resources.
Gazer injects its communication module into an Internet accessible process through which it performs C2.
Gazer performs thread execution hijacking to inject its orchestrator into a running thread from a remote process.
Gazer makes extra efforts to evade detection by changing strings within its code, randomizing markers, and wiping files securely.
Gazer has commands to delete files and persistence mechanisms from the victim.
The second-stage backdoor receives encrypted instructions from the gang via C&C servers, using compromised, legitimate websites as a proxy.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications.
The second-stage backdoor receives encrypted instructions from the gang via C&C servers, using compromised, legitimate websites as a proxy.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
36 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A stealthy Turla backdoor used for cyber-espionage, including spying on embassies.
Malware whose early versions used falsified compilation timestamps.
Backdoor malware that injects a communication module into an Internet-accessible process for command and control.
Backdoor that obtains the current user's security identifier.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.