S1018: Saint Bot
Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.CitationMalwarebytes Saint Bot April 2021CitationPalo Alto Unit 42 OutSteel SaintBot February 2022
Security context for executives and security teams
Saint Bot is a Windows .NET downloader documented by ATT&CK and associated through relationships with Saint Bear and Ember Bear. Its business significance is that a downloader is often an early-stage intrusion component: the key risk is not only the first binary, but what it enables next through command-and-control, tool transfer, discovery, persistence, and evasion behaviors.
Executive priority
Prioritize Saint Bot as a validation case for Windows endpoint resilience, phishing-driven incident readiness, and SOC visibility across early intrusion chains. Leaders should ask whether teams can prove coverage for downloader execution, suspicious scheduled tasks, web-based command-and-control, process injection, registry and system discovery, and follow-on file transfer—not just whether a malware name is blocked.
Technical view
ATT&CK lists Saint Bot as Windows malware and maps it to behaviors including registry, user, process, network, system, file, and directory discovery; PowerShell, command shell, Visual Basic, and Native API execution; scheduled task persistence/execution; obfuscation, packing, masquerading, file deletion, and multiple process injection variants; web protocol C2; local data collection; and ingress tool transfer. SOC and IR teams should validate detections around behavior clusters rather than relying on a Saint Bot signature alone, especially because packing, masquerading, process hollowing, DLL injection, APC injection, and file deletion can reduce artifact-based visibility.
Likely telemetry
- Windows endpoint process creation and command-line telemetry
- PowerShell and script execution logs
- Scheduled task creation, modification, and execution events
- Windows Registry query/access telemetry where available
- File creation, deletion, rename, and directory enumeration events
Detection direction
- Correlate downloader-like execution with rapid discovery activity: registry queries, user discovery, process discovery, system information discovery, network configuration discovery, and file/directory enumeration.
- Tune for suspicious scheduled task creation or recurring execution on Windows, especially when linked to unusual parent processes, recently written binaries, or script interpreters.
- Validate visibility for PowerShell, cmd, Visual Basic, and Native API-mediated execution paths; gaps in script block logging, command-line capture, or EDR process lineage will materially reduce coverage.
- Look for evasion patterns: packed or obfuscated files, names or locations approximating legitimate resources, process hollowing, DLL injection, APC injection, and post-execution file deletion.
- Review web-protocol outbound traffic in context of host behavior. HTTP/S alone is noisy; prioritize rare destinations, new processes initiating connections, and connections following suspicious execution or tool transfer.
Mitigation priorities
- Harden Windows endpoint controls first: restrict unnecessary script execution, monitor or control PowerShell and command shell abuse, and ensure endpoint protection can inspect packed or obfuscated binaries.
- Strengthen persistence controls by monitoring and governing scheduled task creation and changes.
- Improve egress governance and logging for web-protocol command-and-control and external file download paths without assuming all HTTP/S traffic is benign.
- Ensure IR playbooks treat a Saint Bot finding as a possible staging event: scope for downloaded tools, discovery output, scheduled tasks, injected processes, deleted artifacts, and outbound communications.
- Use this object to test compliance evidence for endpoint logging, malware prevention, change monitoring, and incident response readiness on Windows systems.
Additional notes and limits
The ATT&CK object has no official detection text and no malware-level tactics specified, so this take is driven by the official description, Windows platform field, external references, and ATT&CK relationships to techniques and groups. The relationships indicate a broad behavior set consistent with a downloader and follow-on enablement, but each behavior should be validated against local telemetry before drawing incident conclusions.
No official detection guidance, aliases, labels, or explicit malware tactics were supplied. Related technique platform lists include non-Windows platforms because they are generic ATT&CK techniques; Saint Bot itself is only supported here as Windows malware. External reporting is referenced but not expanded beyond the supplied citation metadata.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Saint Bot
Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.CitationMalwarebytes Saint Bot April 2021CitationPalo Alto Unit 42 OutSteel SaintBot February 2022
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
