Threat group.View on attack.mitre.org
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments. |
| T1003.001 LSASS Memory |
Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory. |
| T1003.002 Security Account Manager |
Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as |
| T1003.004 LSA Secrets |
Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture. |
| T1005 Data from Local System |
Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis. |
| T1018 Remote System Discovery |
Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery. |
| T1021 Remote Services |
Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so. |
| T1036 Masquerading |
Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as |
| T1036.005 Match Legitimate Resource Name or Location |
Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments. |
| T1046 Network Service Discovery |
Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments. |
| T1047 Windows Management Instrumentation |
Ember Bear has used WMI execution with password hashes for command execution and lateral movement. |
| T1053.005 Scheduled Task |
Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines. |
| T1059.001 PowerShell |
Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers. |
| T1070.004 File Deletion |
Ember Bear deletes files related to lateral movement to avoid detection. |
| T1071.004 DNS |
Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.