Overview 1 indicators
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.
| domain | 1 | G1003-domain.txt |
Techniques 47 ATT&CK
Open in ATT&CK Navigator → or download the layer (47 techniques, layer 4.5)
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1003.002 Security Account Manager
- T1003.004 LSA Secrets
- T1005 Data from Local System
- T1018 Remote System Discovery
- T1021 Remote Services
- T1036 Masquerading
- T1036.005 Match Legitimate Resource Name or Location
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1059.001 PowerShell
- T1070.004 File Deletion
- T1071.004 DNS
- T1078.001 Default Accounts
- T1090.003 Multi-hop Proxy
- T1095 Non-Application Layer Protocol
- T1110 Brute Force
- T1110.003 Password Spraying
- T1112 Modify Registry
- T1114 Email Collection
- T1119 Automated Collection
- T1125 Video Capture
- T1133 External Remote Services
- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1203 Exploitation for Client Execution
- T1210 Exploitation of Remote Services
- T1491.002 External Defacement
- T1505.003 Web Shell
- T1550.002 Pass the Hash
- T1552.001 Credentials In Files
- T1560 Archive Collected Data
- T1561.002 Disk Structure Wipe
- T1567.002 Exfiltration to Cloud Storage
- T1570 Lateral Tool Transfer
- T1571 Non-Standard Port
- T1572 Protocol Tunneling
- T1583 Acquire Infrastructure
- T1583.003 Virtual Private Server
- T1585 Establish Accounts
- T1588.001 Malware
- T1588.005 Exploits
- T1595.001 Scanning IP Blocks
- T1595.002 Vulnerability Scanning
- T1654 Log Enumeration
Software 11
Principal sources 7 reports
Ranked by how many of this actor's indicators each report brought in.
- 1explore.avertium.com/resource/threat-actor-profile-cadet-bli…
- 1virustotal.com/gui/ip-address/179.43.187.33/detection
- 1virustotal.com/gui/file/20215acd064c02e5aa6ae3996b53f5…
- 1virustotal.com/gui/file/23d6611a730bed886cc3b4ce6780a7…
- 1virustotal.com/gui/file/3e4bb8089657fef9b8e84d9e17fd0d…
- 1virustotal.com/gui/file/3fe9214b33ead5c7d1f80af4695936…
- 1virustotal.com/gui/file/7fedaf0dec060e40cbdf4ec6d0fbfc…
Related groups 8
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 1 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
explore.avertium.com/resource/threat-actor-profile-cadet-bli… · virustotal.com/gui/ip-address/179.43.187.33/detection · virustotal.com/gui/file/20215acd064c02e5aa6ae3996b53f5… · virustotal.com/gui/file/23d6611a730bed886cc3b4ce6780a7… · virustotal.com/gui/file/3e4bb8089657fef9b8e84d9e17fd0d… · virustotal.com/gui/file/3fe9214b33ead5c7d1f80af4695936… · virustotal.com/gui/file/7fedaf0dec060e40cbdf4ec6d0fbfc…
justiceua.org
Further reading 13
- attack.mitre.org/groups/G1003
- unit42.paloaltonetworks.com/ukraine-targeted-outsteel-saintbot
- cisa.gov/sites/default/files/2024-09/aa24-249a-r…
- crowdstrike.com/blog/who-is-ember-bear
- mandiant.com/resources/russia-invasion-ukraine-retal…
- microsoft.com/en-us/security/blog/2023/06/14/cadet-bl…
- virustotal.com/gui/file/20215acd064c02e5aa6ae3996b53f5…
- virustotal.com/gui/file/3e4bb8089657fef9b8e84d9e17fd0d…
- virustotal.com/gui/file/3fe9214b33ead5c7d1f80af4695936…
- virustotal.com/gui/ip-address/179.43.187.33/detection
- virustotal.com/gui/file/7fedaf0dec060e40cbdf4ec6d0fbfc…
- explore.avertium.com/resource/threat-actor-profile-cadet-bli…
- virustotal.com/gui/file/23d6611a730bed886cc3b4ce6780a7…