Gazer

Malware

⚠️ Overview

Gazer (also tracked as WhiteBear) is a sophisticated custom backdoor first documented by ESET in 2016, attributed to the Russia-linked threat actor Turla (aka Snake, Uroburos). It falls under the remote access trojan (RAT) category and has been used extensively in cyberespionage campaigns targeting government and diplomatic entities, particularly in Eastern Europe.

🔧 Technical Capabilities

Gazer operates through a modular architecture with a main loader and encrypted payloads. Propagation occurs via spearphishing emails containing malicious documents (often leveraging CVE-2017-0199 or CVE-2017-8570) to drop the initial dropper. The backdoor communicates with its command-and-control (C2) infrastructure over HTTP using a custom protocol, with traffic disguised as legitimate web requests to trusted domains. Persistence is achieved via registry Run keys or scheduled tasks. Evasion techniques include encrypted configuration files, anti-debugging checks, and dynamic API resolution to avoid static detection. It also uses a technique called “double agent” hooking to bypass user account control. ESET’s 2016 report (welivesecurity.com) details that Gazer can execute commands, download/upload files, and capture keystrokes. MITRE ATT&CK maps Gazer to techniques such as T1059.003 (Command and Scripting Interpreter: Windows Command Shell), T1071.001 (Web Protocols), and T1547.001 (Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder).

📜 History & Notable Incidents

First observed in 2015, Gazer was publicly linked to Turla by ESET in August 2016. It was used in targeted attacks against government ministries in Kazakhstan and Ukraine, as well as embassies in Europe. In 2017, Microsoft attributed a campaign leveraging CVE-2017-0199 to deploy Gazer against Central Asian and Eastern European victims. No law enforcement takedowns have been documented, but the malware remains active as of 2024, with the U.S. CISA including it in its “Known Exploited Vulnerabilities Catalog” (CVE-2017-0199) due to its use in espionage.

🔍 Detection Indicators

File hashes associated with Gazer include SHA256: 2b2b2b... (example placeholder; actual hashes can be found on VirusTotal in ESET's 2016 report). Behavioral indicators include outbound HTTP traffic to .com domains with a User-Agent string mimicking “Mozilla/5.0 (Windows NT 6.1; WOW64; rv:38.0) Gecko/20100101 Firefox/38.0”. Registry persistence is often set in HKCUSoftwareMicrosoftWindowsCurrentVersionRun with a random-named binary. Network IOCs include connections to IP addresses associated with Turla’s C2 infrastructure, as documented by Symantec (broadcom.com) and ESET.

☠️ Risk & Impact

Gazer enables full remote control of compromised systems, allowing data exfiltration of sensitive documents, emails, and credentials. The primary impact is long-term espionage, with financial losses indirect (e.g., stolen diplomatic secrets, intellectual property). Affected sectors include government, defense, and diplomatic missions in Central Asia and Eastern Europe. The U.S. DOJ indictment of Turla operators (2020) cited Gazer as one of the tools used in cyberespionage affecting multiple nations.

🛡️ Mitigation

Defenders should apply patches for CVE-2017-0199 and CVE-2017-8570, implement robust email filtering, deploy YARA rules from ESET’s public repository, and monitor for anomalous HTTP traffic to known Turla C2 domains. Use network segmentation and endpoint detection and response (EDR) tools with behavioral analytics to detect Gazer’s injection and persistence techniques.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.