Waterbear

MITRE ATT&CK: S0579 View on attack.mitre.org

Aliases: DbgPrint, EYEWELL, Waterbear

First seen
2009-01-01 00:00:00
Malware type
loader, backdoor
Family
Malware family
Operating systems
windows
Profile updated
2026-07-07 14:23:01

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services

Targeted regions: country_code:tw country_code:jp country_code:hk

Context

Waterbear is modular malware attributed to BlackTech that has been used primarily for lateral movement, decrypting, and triggering payloads and is capable of hiding network behaviors.

Detection coverage

  • 468 Sigma rules

Malware & tools used

  • DLL (attack-pattern)
  • Thread Execution Hijacking (attack-pattern)
  • Process Injection (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • Modify Registry (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • System Network Connections Discovery (attack-pattern)
  • Query Registry (attack-pattern)
  • Security Software Discovery (attack-pattern)
  • Process Discovery (attack-pattern)
  • Native API (attack-pattern)
  • Indicator Removal from Tools (attack-pattern)
  • Disable or Modify Tools (attack-pattern)

Used by threat actors

Reports & references

  • Mandiant — Chinese Espionage Tactics (report)
  • teamt5.org — Mjib Holds Briefing On Chinese Hackers Attacks On Taiwanese Government Agencies (report)
  • i.blackhat.com — As 21 Tseng Mem2Img Memory Resident Malware Detection Via Convolution Neural Network (report)
  • youtube.com — Watch (report)
  • jsac.jpcert.or.jp — Jsac2020 2 Ycy Aragorn En (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Waterbear (report)
  • Trend Micro — Waterbear Is Back Uses Api Hooking To Evade Security Product Detection (report)
  • daydaynews.cc — 297265 (report)
  • zdnet.com — Waterbear Malware Used In Attack Wave Against Government Agencies (report)
  • MITRE ATT&CK — S0579 (report)

External references