Threat group.View on attack.mitre.org
Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities. Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.
| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload. |
| T1027.013 Encrypted/Encoded File |
Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader. |
| T1059 Command and Scripting Interpreter |
Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines. |
| T1059.001 PowerShell |
Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads. |
| T1059.003 Windows Command Shell |
Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality. |
| T1059.007 JavaScript |
Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot. |
| T1112 Modify Registry |
Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality. |
| T1203 Exploitation for Client Execution |
Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments. |
| T1204.001 Malicious Link |
Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution. |
| T1204.002 Malicious File |
Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems. |
| T1497 Virtualization/Sandbox Evasion |
Saint Bear contains several anti-analysis and anti-virtualization checks. |
| T1553.002 Code Signing |
Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH." |
| T1566.001 Spearphishing Attachment |
Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access. |
| T1583.006 Web Services |
Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations. |
| T1589.002 Email Addresses |
Saint Bear gathered victim email information in advance of phishing operations for targeted attacks. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.