Ember Bear gathers credential material from target systems, such as SSH keys, to facilitate access to victim environments.8
group
Ember Bear G1003
- Created
- 9 June 2022
- Last modified
- 31 July 2026
- Aliases
- Ember Bear · UNC2589 · Bleeding Bear · DEV-0586 · Cadet Blizzard · Frozenvista · UAC-0056
Ember Bear is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).[1] Ember Bear has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.[2] Ember Bear conducted the WhisperGate destructive wiper attacks against Ukraine in early 2022.[3][4][1] There is some confusion as to whether Ember Bear overlaps with another Russian-linked entity referred to as Saint Bear. At present available evidence strongly suggests these are distinct activities with different behavioral profiles.[2][5]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1003
Ember Bear uses legitimate Sysinternals tools such as procdump to dump LSASS memory.910
Ember Bear acquires victim credentials by extracting registry hives such as the Security Account Manager through commands such as reg save.1112
Ember Bear has used frameworks such as Impacket to dump LSA secrets for credential capture.13
Ember Bear gathers victim system information such as enumerating the volume of a given device or extracting system and security event logs for analysis.1415
Ember Bear has used tools such as Nmap and MASSCAN for remote service discovery.16
Standing G1003
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
83rd percentile · 83% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
100th percentile · None of the 176 ATT&CK groups has more tactics spanned — the highest in the population.
84th percentile · 84% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
55th percentile · 55% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1003
1594 distinct rules cover the 47 techniques recorded for this group. The 1797 technique-to-rule mappings resolve to 1594 distinct rules, because one rule can cover several techniques. 1041 Sigma · 553 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org