Also known as: Storm-0587, TA471, UAC-0056, Lorec53, UNC2589, Nascent Ursa, Nodaria, FROZENVISTA, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, likely to collect in
Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )(Citation: Cadet Blizzard emerges as novel threat actor) Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Saint Bear, a Russian-nexus threat actor active since early 2021, primarily targets entities in Ukraine and Georgia. The group is known for using Saint Bot, a remote access tool, and OutSteel, an information stealer, in their campaigns. Saint Bear's tactics include phishing, web-staged malicious documents, and code signing to compromise targets.
Goals & Targeting
Saint Bear appears to target sectors such as government and critical infrastructure within Ukraine and Georgia, possibly for espionage or sabotage purposes. Their use of information-stealing malware indicates an intent to gather sensitive数据, while their focus on Eastern European countries suggests a regional strategic priority.
Enhanced Description
Saint Bear is a cyber threat actor operating with a Russian nexus since early 2021. The group has demonstrated sophistication in crafting malicious tools such as Saint Bot and OutSteel, which are used for remote access and data theft. Saint Bear's campaigns typically involve phishing emails mimicking legitimate entities or distributing malware through malicious documents, often signed to appear trustworthy. The actor's targeting focus on Ukraine and Georgia suggests a possible geopolitical motive, potentially aligned with broader Russian interests in these regions. Saint Bear has been distinguished from other similar groups like Ember Bear through analysis of their tools, behaviors, and victimology.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Saint Bear's campaigns are characterized by their use of phishing and web-staged malicious documents. While specific campaign details are limited, the group's focus on Ukraine and Georgia suggests targeting for political or espionage purposes. Past operations include the deployment of Saint Bot and OutSteel in attacks that likely aimed to gather sensitive data from targeted organizations.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the details of Saint Bear's activities is moderate, as while there is clear evidence of their tools and targeting patterns, specific campaign details remain scarce. The distinctiveness from similar groups like Ember Bear increases confidence in their identity but leaves gaps in understanding their long-term objectives and full operational scope.
No campaigns linked yet.
No observed data linked yet.
28
Techniques
48
Tools
0
Campaigns
15
IOCs
0
Observed Data
7
Tactics