Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ember Bear

Also known as: UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard, Frozenvista, UAC-0056, TA471, Nascent Ursa, Nodaria, Storm-0587, DEV-0587, Saint Bear, Lorec53, EMBER BEAR, Lorec Bear, Ruinous Ursa

Description

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).(Citation: CISA GRU29155 2024) Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.(Citation: Cadet Blizzard emerges as novel threat actor) Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.(Citation: CrowdStrike Ember Bear Profile March 2022)(Citation: Mandiant UNC2589 March 2022)(Citation: CISA GRU29155 2024) There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.(Citation: Cadet Blizzard emerges as novel threat actor)(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )

AI Analysis

· 1 week ago

Executive Summary

Ember Bear, also known as UNC2589, Bleeding Bear, and several other aliases, is a Russian state-sponsored cyber espionage group associated with the GRU's Unit 29155. The group has been active since at least 2020 and has primarily targeted Ukrainian government and telecommunication entities, though it has also attacked critical infrastructure in Europe and the Americas. Known for its use of destructive malware, such as WhisperGate, Ember Bear operates with a mix of advanced persistent threat (APT) tactics and destructive wiper attacks.

Goals & Targeting

Ember Bear's primary strategic objective appears to be conducting cyber espionage and disruptive attacks against Ukrainian government entities, telecommunication networks, and critical infrastructure. The group likely operates under the broader strategic goals of supporting Russian geopolitical interests, particularly in destabilizing Ukraine and other regions where Russia has competing interests. Its targeting of critical infrastructure suggests a focus on disrupting national security and economic stability, while its operations against telecommunications may aim to compromise sensitive communications or gain access to valuable data. Typical victims include government agencies, utility companies, and other key sectors.

Enhanced Description

Ember Bear is a Russian state-sponsored cyber espionage group linked to the Main Intelligence Directorate (GRU) General Staff's 161st Specialist Training Center (Unit 29155). The group has been active since at least 2020 and has primarily targeted Ukrainian government and telecommunication entities. In addition to its focus on Ukraine, Ember Bear has conducted operations against critical infrastructure in Europe and the Americas. Notably, the group is known for its use of destructive malware, such as WhisperGate, which was deployed in early 2022. While there is some confusion about whether Ember Bear overlaps with another Russian-linked entity called Saint Bear, available evidence suggests these are distinct groups with different behavioral profiles. Ember Bear has demonstrated a range of capabilities, including cyber espionage and supply chain compromise, and has been observed using custom tools like reGeorg and P.A.S. Webshell, as well as leveraging known techniques such as malicious PowerShell scripts and credential dumping.

Key Capabilities

  • State-sponsored cyber espionage
  • Destructive malware deployment (e.g., WhisperGate)
  • Advanced persistence techniques
  • Supply chain compromise
  • Custom tools development (reGeorg, P.A.S. Webshell)
  • Credential dumping and lateral movement
  • Network discovery and enumeration

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Exfiltration

ATT&CK Techniques

T1588.005
T1053.005
T1583
T1003
T1491.002
T1133
T1114
T1003.002
T1036.005
T1003.004
T1119
T1036
T1005
T1195
T1190
T1572
T1560
T1021
T1595.002
T1112
T1505.003
T1003.001
T1110.003
T1070.004
T1595.001
T1018
T1046
T1550.002
T1047
T1561.002

Software / Tooling

reGeorg
P.A.S. Webshell
WhisperGate
Saint Bot

Campaigns & Victims

Ember Bear's campaign patterns include targeting critical infrastructure and government entities, often with destructive malware such as WhisperGate. The group has demonstrated a capability for long-term persistence and lateral movement within networks. Notable campaigns include the early 2022 wiper attacks against Ukraine. Victims have included both public sector organizations and private companies in sectors like energy and utilities. Operational tempo suggests a focus on high-impact targets, with an emphasis on disrupting rather than solely stealing data.

IOC Patterns

  • Spear-phishing emails targeting government or critical infrastructure employees
  • Use of PowerShell scripts for initial access and lateral movement
  • Destructive malware deployment (e.g., WhisperGate)
  • Network scanning and enumeration techniques
  • Collection of credentials via LSASS memory dumping
  • Exfiltration of data to external storage services

Recommended Actions

  • Enhance network monitoring for unusual activities, especially PowerShell execution and scheduled task creation.
  • Implement strong defensive measures around critical infrastructure, including regular patching and endpoint detection tools.
  • Monitor for signs of supply chain compromise and third-party vendor access.
  • Secure credentials with multi-factor authentication and limit access to sensitive systems.
  • Conduct regular training sessions on identifying spear-phishing attempts.

Suggested Tags

APT
cyber espionage
state-sponsored
Ukraine
critical infrastructure

Confidence Assessment

Confidence in Ember Bear's identity is high, though some confusion exists regarding overlaps with Saint Bear. The group's operational pattern and toolset suggest a high level of sophistication consistent with state sponsorship. Gaps exist in fully understanding the group's exact motivations beyond its apparent focus on Ukraine, though evidence strongly links it to Russian intelligence services.

ATT&CK Techniques

Collection
5 techniques
Command & Control
5 techniques
Credential Access
7 techniques
Initial Access
2 techniques
Lateral Movement
4 techniques
Resource Development
5 techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. CrowdStrike Ember Bear Profile March 2022 — CrowdStrike. (2022, March 30). Who is EMBER BEAR?. Retrieved June 9, 2022.
  2. Cadet Blizzard emerges as novel threat actor — Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
  3. Mandiant UNC2589 March 2022 — Sadowski, J; Hall, R. (2022, March 4). Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation. Retrieved June 9, 2022.
  4. Palo Alto Unit 42 OutSteel SaintBot February 2022 — Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.
  5. CISA GRU29155 2024 — US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

Intel Summary

47

Techniques

4

Tools

0

Campaigns

0

IOCs

0

Observed Data

14

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
Wiper / Destructive
cyber espionage
state-sponsored
Ukraine
critical infrastructure

Details

MITRE ID
G1003
Type
Unknown
Country of Origin
R
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--a7f57cc1-4540-4429-823f-f4e56b8473c9
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.