Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Saint Bear

Also known as: Storm-0587, TA471, UAC-0056, Lorec53, UNC2589, Nascent Ursa, Nodaria, FROZENVISTA, DEV-0587, Saint Bear, EMBER BEAR, Lorec Bear, Bleeding Bear, Cadet Blizzard, Ruinous Ursa, tracked as, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, likely to collect in

Description

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities.(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )(Citation: Cadet Blizzard emerges as novel threat actor) Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Telecommunications
Healthcare
Education
Manufacturing
Non profit
Energy
Media
Critical infrastructure
Pharmaceutical
Aviation
Hospitality
Aerospace
Retail
Information technology
Think tank
Transportation
Mining
Chemical
Gaming
Legal services
Nuclear
Entertainment
Oil gas
Maritime
Construction
Utilities

Targeted Countries / Regions

CN
UA
US
RU
IR
VN
JP
IL
GB
AU
SA
PK
TW
AE
SG
KR
IN
DE
BY
TR
MX
ES
PL
CA
RO
FR
NG
KP
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

Saint Bear, a Russian-nexus threat actor active since early 2021, primarily targets entities in Ukraine and Georgia. The group is known for using Saint Bot, a remote access tool, and OutSteel, an information stealer, in their campaigns. Saint Bear's tactics include phishing, web-staged malicious documents, and code signing to compromise targets.

Goals & Targeting

Saint Bear appears to target sectors such as government and critical infrastructure within Ukraine and Georgia, possibly for espionage or sabotage purposes. Their use of information-stealing malware indicates an intent to gather sensitive数据, while their focus on Eastern European countries suggests a regional strategic priority.

Enhanced Description

Saint Bear is a cyber threat actor operating with a Russian nexus since early 2021. The group has demonstrated sophistication in crafting malicious tools such as Saint Bot and OutSteel, which are used for remote access and data theft. Saint Bear's campaigns typically involve phishing emails mimicking legitimate entities or distributing malware through malicious documents, often signed to appear trustworthy. The actor's targeting focus on Ukraine and Georgia suggests a possible geopolitical motive, potentially aligned with broader Russian interests in these regions. Saint Bear has been distinguished from other similar groups like Ember Bear through analysis of their tools, behaviors, and victimology.

Key Capabilities

  • Development and deployment of Saint Bot remote access tool
  • Use of OutSteel information stealer
  • Phishing campaigns with malicious documents
  • Web-based malware distribution
  • Code signing for malicious payloads

MITRE ATT&CK Tactics

Persistence
Exfiltration
Lateral Movement
Defense-Evasion
Credential Access

ATT&CK Techniques

T1059.007: JavaScript
T1204.002: Malicious File
T1553.002: Code Signing
T1112: Modify Registry
T1583.006: Web Services
T1059.001: PowerShell
T1203: Exploitation for Client Execution
T1059.003: Windows Command Shell
T1027.002: Software Packing
T1204.001: Malicious Link
T1059: Command and Scripting Interpreter
T1497: Virtualization/Sandbox Evasion
T1685: Disable or Modify Tools
T1684.001: Impersonation

Software / Tooling

Saint Bot
OutSteel

Campaigns & Victims

Saint Bear's campaigns are characterized by their use of phishing and web-staged malicious documents. While specific campaign details are limited, the group's focus on Ukraine and Georgia suggests targeting for political or espionage purposes. Past operations include the deployment of Saint Bot and OutSteel in attacks that likely aimed to gather sensitive data from targeted organizations.

IOC Patterns

  • Spear-phishing emails with malicious documents
  • Web-staged malware distribution via legitimate-looking domains
  • Code-signed malicious binaries
  • JavaScript-based remote access tools

Recommended Actions

  • Implement strong email filtering to detect phishing attempts
  • Monitor for web-based malicious activity and suspicious file downloads
  • Enhance endpoint detection and response (EDR) capabilities
  • Conduct regular code-signing certificate audits to identify anomalies
  • Establish robust network segmentation to limit lateral movement

Suggested Tags

Russian-nexus threat actor
Cyber Espionage
Geopolitical Targeting
Malware Distribution
Information Stealing

Confidence Assessment

Confidence in the details of Saint Bear's activities is moderate, as while there is clear evidence of their tools and targeting patterns, specific campaign details remain scarce. The distinctiveness from similar groups like Ember Bear increases confidence in their identity but leaves gaps in understanding their long-term objectives and full operational scope.

ATT&CK Techniques

Execution
8 techniques
Stealth
6 techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. Cadet Blizzard emerges as novel threat actor — Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
  2. Palo Alto Unit 42 OutSteel SaintBot February 2022 — Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.
  3. attack.mitre.org — Cited by web research for: Sandworm Team
  4. www.crowdstrike.com — Cited by web research for: likely to collect in
  5. attack.mitre.org — Cited by web research for: T1685
  6. research.splunk.com — Cited by web research for: T1098
  7. www.huntress.com — Cited by web research for: STOP

Intel Summary

28

Techniques

48

Tools

0

Campaigns

15

IOCs

0

Observed Data

7

Tactics

Tags

Russian-nexus threat actor
Cyber Espionage
Geopolitical Targeting
Malware Distribution
Information Stealing

Details

MITRE ID
G1031
Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--674582ec-51c4-42ce-b409-797239e37a2a
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.