Ember Bear
Aliases: UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard, Frozenvista, UAC-0056
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.
Open interactive actor investigation
ATT&CK techniques
Remote System DiscoveryT1003
OS Credential DumpingT1090.003
Multi-hop ProxyT1114
Email CollectionT1583
Acquire InfrastructureT1560
Archive Collected DataT1036
MasqueradingT1595.002
Vulnerability ScanningT1583.003
Virtual Private ServerT1654
Log EnumerationT1190
Exploit Public-Facing ApplicationT1133
External Remote ServicesT1119
Automated CollectionT1571
Non-Standard PortT1070.004
File DeletionT1570
Lateral Tool TransferT1095
Non-Application Layer ProtocolT1125
Video CaptureT1572
Protocol TunnelingT1110
Brute ForceT1588.001
MalwareT1110.003
Password SprayingT1595.001
Scanning IP BlocksT1505.003
Web ShellT1585
Establish AccountsT1491.002
External DefacementT1053.005
Scheduled TaskT1210
Exploitation of Remote ServicesT1059.001
PowerShellT1112
Modify RegistryT1071.004
DNST1550.002
Pass the HashT1567.002
Exfiltration to Cloud StorageT1588.005
ExploitsT1195
Supply Chain CompromiseT1562.001
Disable or Modify ToolsT1005
Data from Local SystemT1561.002
Disk Structure WipeT1203
Exploitation for Client ExecutionT1036.005
Match Legitimate Name or LocationT1552.001
Credentials In FilesT1003.001
LSASS MemoryT1047
Windows Management InstrumentationT1021
Remote ServicesT1003.004
LSA SecretsT1003.002
Security Account ManagerT1078.001
Default AccountsT1046
Network Service DiscoveryT1566.001
Spearphishing AttachmentT1588.002
ToolT1588.003
Code Signing CertificatesT1218.002
Control PanelT1027
Obfuscated Files or InformationT1553.002
Code SigningT1027.002
Software PackingT1105
Ingress Tool TransferT1059.007
JavaScriptT1102
Web ServiceT1027.001
Binary PaddingT1566.002
Spearphishing LinkT1059.003
Windows Command ShellT1027.010
Command ObfuscationT1204.002
Malicious FileT1204.001
Malicious Link