Saint Bot

S1018

Malware.View on attack.mitre.org

About this malware

Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.

Techniques used37

Procedure examples37

TechniqueProcedure example
T1005
Data from Local System

Saint Bot can collect files and information from a compromised host.

T1012
Query Registry

Saint Bot has used `check_registry_keys` as part of its environmental checks.

T1016
System Network Configuration Discovery

Saint Bot can collect the IP address of a victim machine.

T1027
Obfuscated Files or Information

Saint Bot has been obfuscated to help avoid detection.

T1027.002
Software Packing

Saint Bot has been packed using a dark market crypter.

T1033
System Owner/User Discovery

Saint Bot can collect the username from a compromised host.

T1036
Masquerading

Saint Bot has renamed malicious binaries as `wallpaper.mp4` and `slideshow.mp4` to avoid detection.

T1036.005
Match Legitimate Resource Name or Location

Saint Bot has been disguised as a legitimate executable, including as Windows SDK.

T1053.005
Scheduled Task

Saint Bot has created a scheduled task named "Maintenance" to establish persistence.

T1055.001
Dynamic-link Library Injection

Saint Bot has injected its DLL component into `EhStorAurhn.exe`.

T1055.004
Asynchronous Procedure Call

Saint Bot has written its payload into a newly-created `EhStorAuthn.exe` process using `ZwWriteVirtualMemory` and executed it using `NtQueueApcThread` and `ZwAlertResumeThread`.

T1055.012
Process Hollowing

The Saint Bot loader has used API calls to spawn `MSBuild.exe` in a suspended state before injecting the decrypted Saint Bot binary into it.

T1057
Process Discovery

Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`.

T1059.001
PowerShell

Saint Bot has used PowerShell for execution.

T1059.003
Windows Command Shell

Saint Bot has used `cmd.exe` and `.bat` scripts for execution.

View all 37 procedure examples

Groups that use it2

Campaigns0

None recorded.

References2

  1. Malwarebytes Saint Bot April 2021 Open source
    Hasherezade. (2021, April 6). A deep dive into Saint Bot, a new downloader. Retrieved June 9, 2022.
  2. Palo Alto Unit 42 OutSteel SaintBot February 2022 Open source
    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.