Saint Bear
Also reported as Storm-0587, TA471, UAC-0056 and Lorec53.
Reports per quarter
Techniques in ATT&CK
Listed by ATT&CK
No report from the last two years names a technique ID.
CVEs named in reports
- CVE-2017-11882 KEV ransomware
- CVE-2020-1472 KEV ransomware
- CVE-2021-1636
- CVE-2021-26084 KEV ransomware
- CVE-2021-32648 KEV
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2022-21999 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-41040 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Overview of the Cyber Weapons Used in the Ukraine - Russia War
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of the Cyber Weapons Used in the Ukraine - Russia War
-
THREAT ANALYSIS REPORT- LockBit 2.0 - All Paths Lead to Ransom
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor THREAT ANALYSIS REPORT- LockBit 2.0 - All Paths Lead to Ransom
Show all 32 reports Show fewer
-
Deep Dive into the Elephant Framework – A New Cyber Threat in Ukraine
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deep Dive into the Elephant Framework – A New Cyber Threat in Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Malpedia Page for GraphSteel
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ukraine CyberWar Overview
-
Elephant Framework Delivered in Phishing Attacks Against Ukrainian Organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Elephant Framework Delivered in Phishing Attacks Against Ukrainian Organizations
-
Cyber Espionage Actor Deploying Malware Using Excel
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Espionage Actor Deploying Malware Using Excel
-
New UAC-0056 activity- There’s a Go Elephant in the room
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New UAC-0056 activity- There’s a Go Elephant in the room
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Who is EMBER BEAR-
-
Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
-
Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Actor UAC-0056 Targeting Ukraine with Fake Translation Software
-
OutSteel, SaintBot Delivered by Spear Phishing Attacks Targeting Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OutSteel, SaintBot Delivered by Spear Phishing Attacks Targeting Ukraine
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spear Phishing Attacks Target Organizations in Ukraine Payloads Include the Document Stealer OutSteel
-
BabaDeda and LorecCPL downloaders used to run Outsteel against Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor BabaDeda and LorecCPL downloaders used to run Outsteel against Ukraine
-
APT Group LOREC53 (Lori Bear) Recently Launched A Large-Scale Cyber Attack On Ukraine
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor APT Group LOREC53 (Lori Bear) Recently Launched A Large-Scale Cyber Attack On Ukraine
Newest first. Details opens the report in Explore.