ATT&CKGroupsEmber Bear

Ember Bear

G1003

Threat group.View on attack.mitre.org

About this group

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.

Techniques used47

Procedure examples47

TechniqueProcedure example
T1003
OS Credential Dumping

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.

T1003.001
LSASS Memory

Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.

T1003.002
Security Account Manager

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.

T1003.004
LSA Secrets

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.

T1005
Data from Local System

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.

T1018
Remote System Discovery

Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.

T1021
Remote Services

Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so.

T1036
Masquerading

Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as dump64.exe to evade detection.

T1036.005
Match Legitimate Resource Name or Location

Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments.

T1046
Network Service Discovery

Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments.

T1047
Windows Management Instrumentation

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.

T1053.005
Scheduled Task

Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines.

T1059.001
PowerShell

Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers.

T1070.004
File Deletion

Ember Bear deletes files related to lateral movement to avoid detection.

T1071.004
DNS

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.

View all 47 procedure examples

Software11

Campaigns0

None recorded.

References5

  1. CISA GRU29155 2024 Open source
    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.
  2. Cadet Blizzard emerges as novel threat actor Open source
    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
  3. CrowdStrike Ember Bear Profile March 2022 Open source
    CrowdStrike. (2022, March 30). Who is EMBER BEAR?. Retrieved June 9, 2022.
  4. Mandiant UNC2589 March 2022 Open source
    Sadowski, J; Hall, R. (2022, March 4). Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation. Retrieved June 9, 2022.
  5. Palo Alto Unit 42 OutSteel SaintBot February 2022 Open source
    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.