Also known as: UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard, Frozenvista, UAC-0056, TA471, Nascent Ursa, Nodaria, Storm-0587, DEV-0587, Saint Bear, Lorec53, EMBER BEAR, Lorec Bear, Ruinous Ursa
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).(Citation: CISA GRU29155 2024) Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.(Citation: Cadet Blizzard emerges as novel threat actor) Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.(Citation: CrowdStrike Ember Bear Profile March 2022)(Citation: Mandiant UNC2589 March 2022)(Citation: CISA GRU29155 2024) There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.(Citation: Cadet Blizzard emerges as novel threat actor)(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )
Executive Summary
Ember Bear, also known as UNC2589, Bleeding Bear, and several other aliases, is a Russian state-sponsored cyber espionage group associated with the GRU's Unit 29155. The group has been active since at least 2020 and has primarily targeted Ukrainian government and telecommunication entities, though it has also attacked critical infrastructure in Europe and the Americas. Known for its use of destructive malware, such as WhisperGate, Ember Bear operates with a mix of advanced persistent threat (APT) tactics and destructive wiper attacks.
Goals & Targeting
Ember Bear's primary strategic objective appears to be conducting cyber espionage and disruptive attacks against Ukrainian government entities, telecommunication networks, and critical infrastructure. The group likely operates under the broader strategic goals of supporting Russian geopolitical interests, particularly in destabilizing Ukraine and other regions where Russia has competing interests. Its targeting of critical infrastructure suggests a focus on disrupting national security and economic stability, while its operations against telecommunications may aim to compromise sensitive communications or gain access to valuable data. Typical victims include government agencies, utility companies, and other key sectors.
Enhanced Description
Ember Bear is a Russian state-sponsored cyber espionage group linked to the Main Intelligence Directorate (GRU) General Staff's 161st Specialist Training Center (Unit 29155). The group has been active since at least 2020 and has primarily targeted Ukrainian government and telecommunication entities. In addition to its focus on Ukraine, Ember Bear has conducted operations against critical infrastructure in Europe and the Americas. Notably, the group is known for its use of destructive malware, such as WhisperGate, which was deployed in early 2022. While there is some confusion about whether Ember Bear overlaps with another Russian-linked entity called Saint Bear, available evidence suggests these are distinct groups with different behavioral profiles. Ember Bear has demonstrated a range of capabilities, including cyber espionage and supply chain compromise, and has been observed using custom tools like reGeorg and P.A.S. Webshell, as well as leveraging known techniques such as malicious PowerShell scripts and credential dumping.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Ember Bear's campaign patterns include targeting critical infrastructure and government entities, often with destructive malware such as WhisperGate. The group has demonstrated a capability for long-term persistence and lateral movement within networks. Notable campaigns include the early 2022 wiper attacks against Ukraine. Victims have included both public sector organizations and private companies in sectors like energy and utilities. Operational tempo suggests a focus on high-impact targets, with an emphasis on disrupting rather than solely stealing data.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in Ember Bear's identity is high, though some confusion exists regarding overlaps with Saint Bear. The group's operational pattern and toolset suggest a high level of sophistication consistent with state sponsorship. Gaps exist in fully understanding the group's exact motivations beyond its apparent focus on Ukraine, though evidence strongly links it to Russian intelligence services.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
47
Techniques
4
Tools
0
Campaigns
0
IOCs
0
Observed Data
14
Tactics