SaintBear
A group targeting UA state organizations using the GraphSteel and GrimPlant malware.
SaintBear is a Russian threat actor targeting Ukrainian state organizations with destructive WhisperGate malware operations.
SaintBear, also tracked as UNC2589, is a Russian threat actor primarily targeting Ukrainian state organizations. Their TTPs include vulnerability scanning, exploitation of public-facing applications, brute force, and leveraging tools like Impacket and Scheduled Tasks for lateral movement; they have deployed the WhisperGate malware in destructive operations. Defenders should focus on monitoring public-facing services, detecting brute-force patterns, anomalous usage of legitimate tools like PsExec and Responder, and especially email collection attempts.
A group targeting UA state organizations using the GraphSteel and GrimPlant malware.
Network traffic should be monitored for Vulnerability Scanning activity and anomalies investigated.
New host or domain registrations should be monitored to detect infrastructure changes.
Web Application Firewall (WAF) should be used to detect Exploit attempts on public-facing applications.
Security products should monitor Scheduled Task creation and modification, and block unnecessary ones.
Access attempts to External Remote Services should be monitored and only allowed for necessary users.
Masquerading attempts should be detected by monitoring system file and process names and attributes.
Login attempts should be monitored to detect Brute Force attacks and rate limiting enforced.
Abnormal network and system queries for Remote System Discovery and Log Enumeration should be monitored.
File transfers and executed files on the network should be monitored to detect Lateral Tool Transfer.
Abnormal activities on email servers and clients should be monitored to detect Email Collection.
Suspicious network traffic using Non-Standard Port and Multi-hop Proxy should be monitored and blocked.
Network traffic related to cloud storage services should be monitored to detect Exfiltration to Cloud Storage.
Registry changes should be monitored to detect Modify Registry attempts and unnecessary changes blocked.
Public-facing web pages should be regularly monitored to detect External Defacement and changes investigated.
SaintBear, also tracked as UNC2589, is a Russian threat actor primarily targeting Ukrainian state organizations.
The SaintBear actor has deployed the WhisperGate malware in destructive operations.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.