Saint Bot
MITRE ATT&CK: S1018 View on attack.mitre.org
Aliases: Saint Bot
- First seen
- 2021-03-01 00:00:00
- Malware type
- downloader
- Family
- Malware family
- Operating systems
- windows
- Profile updated
- 2026-07-07 13:01:03
Targeted industries: government-and-public-sector financial-services technology-and-telecommunications
Context
Saint Bot is a .NET downloader that has been used by Saint Bear since at least March 2021.
Detection coverage
- 837 Sigma rules
Malware & tools used
- Regsvr32 (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Bypass User Account Control (attack-pattern)
- Obfuscated Files or Information (attack-pattern)
- Masquerading (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- Web Protocols (attack-pattern)
- System Information Discovery (attack-pattern)
- Windows Command Shell (attack-pattern)
- Time Based Checks (attack-pattern)
- Query Registry (attack-pattern)
- Scheduled Task (attack-pattern)
- Native API (attack-pattern)
- Malicious File (attack-pattern)
- Asynchronous Procedure Call (attack-pattern)
- Spearphishing Link (attack-pattern)
- Software Packing (attack-pattern)
- Visual Basic (attack-pattern)
- System Checks (attack-pattern)
- PowerShell (attack-pattern)
- Debugger Evasion (attack-pattern)
- System Location Discovery (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
Used by threat actors
- Ember Bear (threat-actor)
- Saint Bear (threat-actor)
Reports & references
- Palo Alto Unit 42 — Nascentursa (report)
- Palo Alto Unit 42 — Ukraine Targeted Outsteel Saintbot (report)
- inquest.net — Ukraine Cyberwar Overview (report)
- lifars.com — A Closer Look At The Russian Actors Targeting Organizations In Ukraine (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Saint Bot (report)
- CERT-UA — 18419 (report)
- blog.malwarebytes.com — A Deep Dive Into Saint Bot Downloader (report)
- cyberscoop.com — Ukrainian Cyber Attacks Russia Conflict Q And A (report)
- MITRE ATT&CK — S1018 (report)
- blog.malwarebytes.com — A Deep Dive Into Saint Bot Downloader (report)