ATT&CKGroupsSaint Bear

Saint Bear

G1031

Threat group.View on attack.mitre.org

About this group

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities. Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1027.002
Software Packing

Saint Bear clones .NET assemblies from other .NET binaries as well as cloning code signing certificates from other software to obfuscate the initial loader payload.

T1027.013
Encrypted/Encoded File

Saint Bear initial payloads included encoded follow-on payloads located in the resources file of the first-stage loader.

T1059
Command and Scripting Interpreter

Saint Bear has used the Windows Script Host (wscript) to execute intermediate files written to victim machines.

T1059.001
PowerShell

Saint Bear relies extensively on PowerShell execution from malicious attachments and related content to retrieve and execute follow-on payloads.

T1059.003
Windows Command Shell

Saint Bear initial loaders will also drop a malicious Windows batch file, available via open source GitHub repositories, that disables Microsoft Defender functionality.

T1059.007
JavaScript

Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.

T1112
Modify Registry

Saint Bear will leverage malicious Windows batch scripts to modify registry values associated with Windows Defender functionality.

T1203
Exploitation for Client Execution

Saint Bear has leveraged vulnerabilities in client applications such as CVE-2017-11882 in Microsoft Office to enable code execution in victim environments.

T1204.001
Malicious Link

Saint Bear has, in addition to email-based phishing attachments, used malicious websites masquerading as legitimate entities to host links to malicious files for user execution.

T1204.002
Malicious File

Saint Bear relies on user interaction and execution of malicious attachments and similar for initial execution on victim systems.

T1497
Virtualization/Sandbox Evasion

Saint Bear contains several anti-analysis and anti-virtualization checks.

T1553.002
Code Signing

Saint Bear has used an initial loader malware featuring a legitimate code signing certificate associated with "Electrum Technologies GmbH."

T1566.001
Spearphishing Attachment

Saint Bear uses a variety of file formats, such as Microsoft Office documents, ZIP archives, PDF documents, and other items as phishing attachments for initial access.

T1583.006
Web Services

Saint Bear has leveraged the Discord content delivery network to host malicious content for retrieval during initial access operations.

T1589.002
Email Addresses

Saint Bear gathered victim email information in advance of phishing operations for targeted attacks.

View all 18 procedure examples

Software2

Campaigns0

None recorded.

References2

  1. Cadet Blizzard emerges as novel threat actor Open source
    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.
  2. Palo Alto Unit 42 OutSteel SaintBot February 2022 Open source
    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.