FORENSIA

THREAT_ACTOR · G1031

Saint Bear

Also known as: Saint Bear, Storm-0587, TA471, UAC-0056, Lorec53

Profile

Saint Bear is a Russian-nexus threat actor active since early 2021, primarily targeting entities in Ukraine and Georgia. The group is notable for a specific remote access tool, Saint Bot, and information stealer, OutSteel in campaigns. Saint Bear typically relies on phishing or web staging of malicious documents and related file types for initial access, spoofing government or related entities. Saint Bear has previously been confused with Ember Bear operations, but analysis of behaviors, tools, and targeting indicates these are distinct clusters.

MITRE ATT&CK ↗

Techniques

18 ATT&CK techniques attributed to this actor.

Software

2 malware/tools attributed to this actor.

OutSteelSaint Bot

Related corpus activity

9,844 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Saint Bear.

IndicatorTypeFamilySevSrc
cve-2025-12057cve851
cve-2016-5681cve852
cve-2018-8007cve851
cve-2026-3844cve851
cve-2025-1055cveransomware853
cve-2025-61155cveransomware853
cve-2013-3307cve852
cve-2024-1781cve851
cve-2026-4368cveransomware851
cve-2026-0740cve851
cve-2025-7852cve851
cve-2023-52271cveransomware853
cve-2016-0638cvephishing851
cve-2017-17215cve852
cve-2022-47945cve851
cve-2021-27076cve851
cve-2025-11837cve852
cve-2025-68670cve852
cve-2026-3102cve853
cve-2023-44976cveransomware852
cve-2021-29441cve851
cve-2026-1969cve851
cve-2025-34085cve851
cve-2025-7443cve851
61e9d76f07334843df561fe4bac449fb6fdaed5e5eb91480bded225f3d265c5fhashphishing802
82e579bd49d69845133c9aa8585f8bd26736437bhash802
bd46890121106b43f0c01ab82629400chashcryptojacking802
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
7105caa6d4fd8a2c67523d385277528e556ae4f6hash802
44a4ac119349f525d877728b53fe38453a516881d577679caf08ab69312a695fsha256phishing802

Showing the top 30 by severity of 9,844.