LiveActive security incident?Get immediate response
MITRE ATT&CK® Group

G1003: Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

EnterpriseG1003GroupObject v2.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

G1003: Ember Bear describes [Ember Bear](https://attack.mitre.org/groups/G1003) is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).(Citation: CISA GRU29155 2024) [Ember Bear](https://attack.mitre.org/groups/G1003) has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Am...

Executive priority

G1003: Ember Bear is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate G1003: Ember Bear by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether G1003: Ember Bear appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Ember Bear

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

47 rows
DomainIDNameRelationship / procedure
EnterpriseT1018Remote System Discovery

Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.[1]

EnterpriseT1090.003Multi-hop ProxySub-technique

Ember Bear has configured multi-hop proxies via ProxyChains within victim environments.[1]

EnterpriseT1114Email Collection

Ember Bear attempts to collect mail from accessed systems and servers.[2][1]

EnterpriseT1583Acquire Infrastructure

Ember Bear uses services such as IVPN, SurfShark, and Tor to add anonymization to operations.[2]

EnterpriseT1560Archive Collected Data

Ember Bear has compressed collected data prior to exfiltration.[1]

EnterpriseT1036Masquerading

Ember Bear has renamed the legitimate Sysinternals tool procdump to alternative names such as dump64.exe to evade detection.[2]

EnterpriseT1595.002Vulnerability ScanningSub-technique

Ember Bear has used publicly available tools such as MASSCAN and Acunetix for vulnerability scanning of public-facing infrastructure.[1]

EnterpriseT1583.003Virtual Private ServerSub-technique

Ember Bear has used virtual private servers (VPSs) to host tools, perform reconnaissance, exploit victim infrastructure, and as a destination for data exfiltration.[1]

EnterpriseT1654Log Enumeration

Ember Bear has enumerated SECURITY and SYSTEM log files during intrusions.[1]

EnterpriseT1190Exploit Public-Facing Application

Ember Bear gains initial access to victim environments by exploiting external-facing services. Examples include exploitation of CVE-2021-26084 in Confluence servers; CVE-2022-41040, ProxyShell, and other vulnerabilities in Microsoft Exchange; and multiple vulnerabilities in open-source platforms such as content management systems.[2][1]

EnterpriseT1133External Remote Services

Ember Bear have used VPNs both for initial access to victim environments and for persistence within them following compromise.[1]

EnterpriseT1119Automated Collection

Ember Bear engages in mass collection from compromised systems during intrusions.[2]

EnterpriseT1571Non-Standard Port

Ember Bear has used various non-standard ports for C2 communication.[1]

EnterpriseT1070.004File DeletionSub-technique

Ember Bear deletes files related to lateral movement to avoid detection.[2]

EnterpriseT1570Lateral Tool Transfer

Ember Bear retrieves follow-on payloads direct from adversary-owned infrastructure for deployment on compromised hosts.[2]

EnterpriseT1095Non-Application Layer Protocol

Ember Bear uses socket-based tunneling utilities for command and control purposes such as NetCat and Go Simple Tunnel (GOST). These tunnels are used to push interactive command prompts over the created sockets.[2] Ember Bear has also used reverse TCP connections from Meterpreter installations to communicate back with C2 infrastructure.[1]

EnterpriseT1125Video Capture

Ember Bear has exfiltrated images from compromised IP cameras.[1]

EnterpriseT1572Protocol Tunneling

Ember Bear has used ProxyChains to tunnel protocols to internal networks.[1]

EnterpriseT1110Brute Force

Ember Bear used the `su-bruteforce` tool to brute force specific users using the `su` command.[1]

EnterpriseT1588.001MalwareSub-technique

Ember Bear has acquired malware and related tools from dark web forums.[1]

EnterpriseT1110.003Password SprayingSub-technique

Ember Bear has conducted password spraying against Outlook Web Access (OWA) infrastructure to identify valid user names and passwords.[1]

EnterpriseT1595.001Scanning IP BlocksSub-technique

Ember Bear has targeted IP ranges for vulnerability scanning related to government and critical infrastructure organizations.[1]

EnterpriseT1505.003Web ShellSub-technique

Ember Bear deploys web shells following initial access for either follow-on command execution or protocol tunneling. Example web shells used by Ember Bear include P0wnyshell, reGeorg, P.A.S. Webshell, and custom variants of publicly-available web shell examples.[2][1]

EnterpriseT1585Establish Accounts

Ember Bear has created accounts on dark web forums to obtain various tools and malware.[1]

EnterpriseT1491.002External DefacementSub-technique

Ember Bear is linked to the defacement of several Ukrainian organization websites.[2]

EnterpriseT1053.005Scheduled TaskSub-technique

Ember Bear uses remotely scheduled tasks to facilitate remote command execution on victim machines.[2]

EnterpriseT1059.001PowerShellSub-technique

Ember Bear has used PowerShell commands to gather information from compromised systems, such as email servers.[1]

EnterpriseT1112Modify Registry

Ember Bear modifies registry values for anti-forensics and defense evasion purposes.[2]

EnterpriseT1071.004DNSSub-technique

Ember Bear has used DNS tunnelling tools, such as dnscat/2 and Iodine, for C2 purposes.[1]

EnterpriseT1550.002Pass the HashSub-technique

Ember Bear has used pass-the-hash techniques for lateral movement in victim environments.[1]

EnterpriseT1567.002Exfiltration to Cloud StorageSub-technique

Ember Bear has used tools such as Rclone to exfiltrate information from victim environments to cloud storage such as `mega.nz`.[1]

EnterpriseT1588.005ExploitsSub-technique

Ember Bear has obtained exploitation scripts against publicly-disclosed vulnerabilities from public repositories.[1]

EnterpriseT1195Supply Chain Compromise

Ember Bear has compromised information technology providers and software developers providing services to targets of interest, building initial access to ultimate victims at least in part through compromise of service providers that work with the victim organizations.[2]

EnterpriseT1005Data from Local System

Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.[2][1]

EnterpriseT1561.002Disk Structure WipeSub-technique

Ember Bear conducted destructive operations against victims, including disk structure wiping, via the WhisperGate malware in Ukraine.[2]

EnterpriseT1203Exploitation for Client Execution

Ember Bear has used exploits to enable follow-on execution of frameworks such as Meterpreter.[1]

EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

Ember Bear has renamed tools to match legitimate utilities, such as renaming GOST tunneling instances to `java` in victim environments.[1]

EnterpriseT1552.001Credentials In FilesSub-technique

Ember Bear has dumped configuration settings in accessed IP cameras including plaintext credentials.[1]

EnterpriseT1003.001LSASS MemorySub-technique

Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.[2][1]

EnterpriseT1047Windows Management Instrumentation

Ember Bear has used WMI execution with password hashes for command execution and lateral movement.[1]

EnterpriseT1021Remote Services

Ember Bear uses valid network credentials gathered through credential harvesting to move laterally within victim networks, often employing the Impacket framework to do so.[2]

EnterpriseT1003.004LSA SecretsSub-technique

Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.[1]

EnterpriseT1003.002Security Account ManagerSub-technique

Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.[2][1]

EnterpriseT1078.001Default AccountsSub-technique

Ember Bear has abused default user names and passwords in externally-accessible IP cameras for initial access.[1]

EnterpriseT1046Network Service Discovery

Ember Bear has used tools such as NMAP for remote system discovery and enumeration in victim environments.[1]

EnterpriseT1210Exploitation of Remote Services

Ember Bear has used exploits for vulnerabilities such as MS17-010, also known as `Eternal Blue`, during operations.[1]

EnterpriseT1003OS Credential Dumping

Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.[2]

Associated objects

Groups, software, and campaigns

ToolEnterprise

S0488: CrackMapExec

CrackMapExec, or CME, is a post-exploitation tool developed in Python and designed for penetration testing against networks. CrackMapExec collects Active Directory information to conduct lateral movement through targeted networks.[1]

Windows
ToolEnterprise

S0174: Responder

Responder is an open source tool used for LLMNR, NBT-NS and MDNS poisoning, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. [1]

ToolEnterprise

S0508: ngrok

ngrok is a legitimate reverse proxy tool that can create a secure tunnel to servers located behind firewalls or on local machines that do not have a public IP. ngrok has been leveraged by threat actors in several campaigns including use for lateral movement and data exfiltration.[1][2][3][4]

Windows
MalwareEnterprise

S1187: reGeorg

reGeorg is an open-source web shell written in Python that can be used as a proxy to bypass firewall rules and tunnel data in and out of targeted networks.[1][2]

Network DevicesWindowsmacOS
MalwareEnterprise

S0689: WhisperGate

WhisperGate is a multi-stage wiper designed to look like ransomware that has been used against multiple government, non-profit, and information technology organizations in Ukraine since at least January 2022.[1][2][3]

Windows
ToolEnterprise

S0029: PsExec

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.[1][2]

Windows
ToolEnterprise

S1040: Rclone

Rclone is a command line program for syncing files with cloud storage services such as Dropbox, Google Drive, Amazon S3, and MEGA. Rclone has been used in a number of ransomware campaigns, including those associated with the Conti and DarkSide Ransomware-as-a-Service operations.[1][2][3][4][5]

LinuxWindowsmacOS
ToolEnterprise

S0357: Impacket

Impacket is an open source collection of modules written in Python for programmatically constructing and manipulating network protocols. Impacket contains several tools for remote service execution, Kerberos manipulation, Windows credential dumping, packet sniffing, and relay attacks.[1]

LinuxmacOSWindows
Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
2.1
Created
Modified
Raw hash
94b27d5ca1cb5c41...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.22.1Current bundle94b27d5ca1cb…
19.12.1Older bundlee5c2595965fb…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    CISA GRU29155 2024

    US Cybersecurity & Infrastructure Security Agency et al. (2024, September 5). Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure. Retrieved September 6, 2024.

    Open source URL
  2. [2]
    Cadet Blizzard emerges as novel threat actor

    Microsoft Threat Intelligence. (2023, June 14). Cadet Blizzard emerges as a novel and distinct Russian threat actor. Retrieved July 10, 2023.

    Open source URL
  3. [3]
    CrowdStrike Ember Bear Profile March 2022

    CrowdStrike. (2022, March 30). Who is EMBER BEAR?. Retrieved June 9, 2022.

    Open source URL
  4. [4]
    Mandiant UNC2589 March 2022

    Sadowski, J; Hall, R. (2022, March 4). Responses to Russia's Invasion of Ukraine Likely to Spur Retaliation. Retrieved June 9, 2022.

    Open source URL
  5. [5]
    Palo Alto Unit 42 OutSteel SaintBot February 2022

    Unit 42. (2022, February 25). Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBot. Retrieved June 9, 2022.

    Open source URL
  6. [6]
    Bleeding Bear

    (Citation: CrowdStrike Ember Bear Profile March 2022)

  7. [7]
    Cadet Blizzard

    (Citation: Cadet Blizzard emerges as novel threat actor)

  8. [8]
    DEV-0586

    (Citation: Cadet Blizzard emerges as novel threat actor)

  9. [9]
    Frozenvista

    (Citation: CISA GRU29155 2024)

  10. [10]
    UAC-0056

    (Citation: CISA GRU29155 2024)

  11. [11]
    UNC2589

    (Citation: Mandiant UNC2589 March 2022)

  12. [12]
    mitre-attackG1003
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.