All actors

Ember Bear

Also reported as DEV-0586, Cadet Blizzard, UNC2589, UAC-0056, Bleeding Bear and 13 other names. Linked to Russia by four sources.

Reports
68
Last reported
Known CVEs
38
Techniques in ATT&CK
47
Origin
Russia
ID
G1003
Merge evidence
31 alias matches

Reports per quarter

  1. 2022 Q1: 31 reports
  2. 2022 Q2: 10 reports
  3. 2022 Q3: 5 reports
  4. 2022 Q4: no reports
  5. 2023 Q1: 6 reports
  6. 2023 Q2: 3 reports
  7. 2023 Q3: no reports
  8. 2023 Q4: no reports
  9. 2024 Q1: no reports
  10. 2024 Q2: 2 reports
  11. 2024 Q3: 3 reports
  12. 2024 Q4: no reports
  13. 2025 Q1: no reports
  14. 2025 Q2: no reports
  15. 2025 Q3: 1 report
  16. 2025 Q4: no reports
  17. 2026 Q1: no reports
  18. 2026 Q2: 7 reports
Dated reports, 2022 Q1 to 2026 Q2.

Techniques in ATT&CK

Listed by ATT&CK

Show all 47 techniques Show fewer

No report from the last two years names a technique ID.

CVEs named in reports

Show all 38 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. WhisperGate (Malware Family)

    date ORKL added it fromORKL

  2. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

Show all 68 reports Show fewer
  1. Microsoft Security Compliance and Identity

    Malpedia library date Microsoft fromORKL

  2. Malpedia Page for GraphSteel

    date in the title fromORKL

  3. Ukraine CyberWar Overview

    date in the title fromORKL

  4. Cyber Espionage Actor Deploying Malware Using Excel

    date in the title fromORKL

  5. New UAC-0056 activity- There’s a Go Elephant in the room

    date in the title fromORKL

  6. Who is EMBER BEAR-

    date in the title fromORKL

  7. Cyber threat activity in Ukraine- analysis and resources

    date in the title fromORKL

  8. Threat Update – Ukraine & Russia conflict

    date in the title fromORKL

  9. ACTINIUM targets Ukrainian organizations

    date in the title fromORKL

  10. ACTINIUM targets Ukrainian organizations

    date in the CCS '25 data microsoft fromORKLCCS '25 data

  11. WhisperGate Malware Corrupts Computers in Ukraine

    date in the title fromORKL

  12. Netskope Threat Coverage- WhisperGate

    date in the title fromORKL

  13. Threat Brief- Ongoing Russia and Ukraine Cyber Conflict

    date in the title fromORKL

  14. Operation Bleeding Bear

    date in the title fromORKL

  15. Malware attacks targeting Ukraine government (DEV-0586)

    date in the title fromORKL

Newest first. Details opens the report in Explore.