Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S1018
MITRE ATT&CK Malware

Saint Bot (S1018)

ShareXLinkedInRedditHN

[Saint Bot](https://attack.mitre.org/software/S1018) is a .NET downloader that has been used by [Saint Bear](https://attack.mitre.org/groups/G1031) since at least March 2021.(Citation: Malwarebytes Saint Bot April 2021)(Citation: Palo Alto Unit 42 OutSteel SaintBot February 2022 )

Platforms: Windows

▪Techniques implemented (37)

T1218.010Regsvr32T1055.001Dynamic-link Library InjectionT1016System Network Configuration DiscoveryT1548.002Bypass User Account ControlT1027Obfuscated Files or InformationT1036MasqueradingT1105Ingress Tool TransferT1071.001Web ProtocolsT1082System Information DiscoveryT1059.003Windows Command ShellT1497.003Time Based ChecksT1012Query RegistryT1053.005Scheduled TaskT1106Native APIT1204.002Malicious FileT1055.004Asynchronous Procedure CallT1566.002Spearphishing LinkT1027.002Software PackingT1059.005Visual BasicT1497.001System ChecksT1059.001PowerShellT1622Debugger EvasionT1614System Location DiscoveryT1547.001Registry Run Keys / Startup FolderT1140Deobfuscate/Decode Files or InformationT1055.012Process HollowingT1057Process DiscoveryT1566.001Spearphishing AttachmentT1036.005Match Legitimate Resource Name or LocationT1083File and Directory DiscoveryT1574Hijack Execution FlowT1033System Owner/User DiscoveryT1218.004InstallUtilT1204.001Malicious LinkT1132.001Standard EncodingT1070.004File DeletionT1005Data from Local System

▪Used by groups (2)

G1003Ember BearG1031Saint Bear
S1018on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.