Intrusion setG1003

Ember Bear

Also tracked as UNC2589, Bleeding Bear, DEV-0586, Cadet Blizzard, Frozenvista, UAC-0056

Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155). Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas. Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022. There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.

Documented techniques
47
Assessed origin
Russia
Assessed motivation
Espionage, Sabotage
First seen
2020
Basis
MITRE ATT&CK

How they break in

Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.

Malware

Families MITRE records this group deploying. Detection names for these are a reasonable place to start.

P.A.S. WebshellSaint BotWhisperGatereGeorg

Tools

Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.

BloodHoundCrackMapExecImpacketPsExecRcloneResponderngrok
Source: MITRE ATT&CK View the original record · Last synchronised 2026-09-09 · Origin and motivation are read from MITRE’s own description and are not structured fields in ATT&CK. Where the text does not attribute a group, this page leaves them blank rather than guessing.