Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 20:10:34 UTC Home > List all groups > List all tools > List all groups using tool WhiteAtlas Tool: WhiteAtlas Names WhiteAtlas Category Malware Type Dropper Description (Kaspersky) The White Atlas framework often utilized a small Javascript script to execute the malware dropper payload after it was decrypted by the VBA macro code, then to delete the dropper afterwards. A much more advanced and highly obfuscated Javascript script was utilized in White Atlas samples that dropped a Firefox extension backdoor developed by Turla, but again the script was responsible for the simple tasks of writing out the extension.json configuration file for the extension and deleting itself for cleanup purposes. Information Last change to this tool card: 20 April 2020 Download this tool card in JSON format All groups using tool WhiteAtlas Changed Name Country Observed APT groups Turla, Waterbug, Venomous Bear 1996-2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c3f21a5b-b2fa-4c71-a4bc-8295b78e10cc https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c3f21a5b-b2fa-4c71-a4bc-8295b78e10cc Page 1 of 1