Ember Bear
Also reported as DEV-0586, Cadet Blizzard, UNC2589, UAC-0056, Bleeding Bear and 13 other names. Linked to Russia by four sources.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
Show all 47 techniques Show fewer
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2017-11882 KEV ransomware
- CVE-2020-12641 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-35730 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-26084 KEV ransomware
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-32648 KEV
- CVE-2021-33044 KEV
- CVE-2021-33045 KEV
Show all 38 CVEs Show fewer
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2022-1388 KEV ransomware
- CVE-2022-21919 KEV
- CVE-2022-22954 KEV ransomware
- CVE-2022-22960 KEV
- CVE-2022-22972
- CVE-2022-26134 KEV ransomware
- CVE-2022-26138 KEV
- CVE-2022-27666
- CVE-2022-30190 KEV ransomware
- CVE-2022-3236 KEV
- CVE-2022-3802
- CVE-2022-38028 KEV
- CVE-2022-41040 KEV ransomware
- CVE-2022-41352 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-2868 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor WhisperGate (Malware Family)
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
Show all 68 reports Show fewer
-
Microsoft Security Compliance and Identity
The original link failed its last check. Original publisher Detailsfor Microsoft Security Compliance and Identity
-
Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Graphiron: New Russian Information Stealing Malware Deployed Against Ukraine
-
Graphiron- New Russian Information Stealing Malware Deployed Against Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Graphiron- New Russian Information Stealing Malware Deployed Against Ukraine
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
Evacuation and Humanitarian Documents used to Spear Phish Ukrainian Entities
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Evacuation and Humanitarian Documents used to Spear Phish Ukrainian Entities
-
Deep Dive into the Elephant Framework – A New Cyber Threat in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Dive into the Elephant Framework – A New Cyber Threat in Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malpedia Page for GraphSteel
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
Elephant Framework Delivered in Phishing Attacks Against Ukrainian Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elephant Framework Delivered in Phishing Attacks Against Ukrainian Organizations
-
Cyber Espionage Actor Deploying Malware Using Excel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Espionage Actor Deploying Malware Using Excel
-
New UAC-0056 activity- There’s a Go Elephant in the room
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New UAC-0056 activity- There’s a Go Elephant in the room
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is EMBER BEAR-
-
Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
-
Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
-
Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation
-
Elastic protects against data wiper malware targeting Ukraine- HERMETICWIPER
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elastic protects against data wiper malware targeting Ukraine- HERMETICWIPER
-
Cyber threat activity in Ukraine- analysis and resources
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber threat activity in Ukraine- analysis and resources
-
Threat Update – Ukraine & Russia conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Update – Ukraine & Russia conflict
-
ACTINIUM targets Ukrainian organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor ACTINIUM targets Ukrainian organizations
-
ACTINIUM targets Ukrainian organizations
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ACTINIUM targets Ukrainian organizations
-
WhisperGate Malware Corrupts Computers in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor WhisperGate Malware Corrupts Computers in Ukraine
-
Netskope Threat Coverage- WhisperGate
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Netskope Threat Coverage- WhisperGate
-
Threat Brief- Ongoing Russia and Ukraine Cyber Conflict
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Brief- Ongoing Russia and Ukraine Cyber Conflict
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Bleeding Bear
-
Malware attacks targeting Ukraine government (DEV-0586)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malware attacks targeting Ukraine government (DEV-0586)
-
Destructive malware targeting Ukrainian organizations (DEV-0586)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Destructive malware targeting Ukrainian organizations (DEV-0586)
Newest first. Details opens the report in Explore.