Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1003
MITRE ATT&CK Group

Ember Bear (G1003)

UNC2589Bleeding BearDEV-0586Cadet BlizzardFrozenvistaUAC-0056
ShareXLinkedInRedditHN

[Ember Bear](https://attack.mitre.org/groups/G1003) is a Russian state-sponsored cyber espionage group that has been active since at least 2020, linked to Russia's General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155).(Citation: CISA GRU29155 2024) [Ember Bear](https://attack.mitre.org/groups/G1003) has primarily focused operations against Ukrainian government and telecommunication entities, but has also operated against critical infrastructure entities in Europe and the Americas.(Citation: Cadet Blizzard emerges as novel threat actor) [Ember Bear](https://attack.mitre.org/groups/G1003) conducted the [WhisperGate](https://attack.mitre.org/software/S0689) destructive wiper attacks against Ukraine in early 2022.(Citation: CrowdStrike Ember Bear Profile March 2022)(Citation: Mandiant UNC2589 March 2022)(Citation: CISA GRU29155 2024) There is some confusion as to whether [Ember Bear](https://attack.mitre.org/groups/G1003) overlaps with another Russian-linked entity referred to as [Saint Bear](https://attack.mitre.org/groups/G1031). At present available evidence strongly suggests these are distinct activities with different behavioral profiles.(Citation: Cadet Blizzard emerges as novel threat actor)(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )

▪Techniques used (47)

T1018Remote System DiscoveryT1003OS Credential DumpingT1090.003Multi-hop ProxyT1114Email CollectionT1583Acquire InfrastructureT1560Archive Collected DataT1036MasqueradingT1595.002Vulnerability ScanningT1583.003Virtual Private ServerT1654Log EnumerationT1190Exploit Public-Facing ApplicationT1133External Remote ServicesT1119Automated CollectionT1571Non-Standard PortT1070.004File DeletionT1570Lateral Tool TransferT1095Non-Application Layer ProtocolT1125Video CaptureT1572Protocol TunnelingT1110Brute ForceT1588.001MalwareT1110.003Password SprayingT1595.001Scanning IP BlocksT1505.003Web ShellT1585Establish AccountsT1491.002External DefacementT1053.005Scheduled TaskT1210Exploitation of Remote ServicesT1059.001PowerShellT1112Modify RegistryT1071.004DNST1550.002Pass the HashT1567.002Exfiltration to Cloud StorageT1588.005ExploitsT1195Supply Chain CompromiseT1005Data from Local SystemT1561.002Disk Structure WipeT1203Exploitation for Client ExecutionT1036.005Match Legitimate Resource Name or LocationT1552.001Credentials In FilesT1003.001LSASS MemoryT1047Windows Management InstrumentationT1021Remote ServicesT1003.004LSA SecretsT1003.002Security Account ManagerT1078.001Default AccountsT1046Network Service Discovery

▪Software used (11)

S0598P.A.S. WebshellmalwareS0488CrackMapExectoolS0174RespondertoolS0508ngroktoolS1187reGeorgmalwareS0689WhisperGatemalwareS1018Saint BotmalwareS0029PsExectoolS1040RclonetoolS0521BloodHoundtoolS0357Impackettool
G1003on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.