Saint Bear

APT / StateG1031 ↗
Origin🇷🇺 Rússia
Techniques (MITRE ATT&CK)18
SourceMITRE ATT&CK
0
Also known as:Bleeding BearCadet BlizzardDEV-0587EMBER BEARFROZENVISTALorec BearLorec53Nascent UrsaNodariaStorm-0587TA471UAC-0056UNC2589

About the group

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities. Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity42
Impact: High
T1566.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionCommand andScripting Interpr…

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities 1

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Saint Bear uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →