APT / THREAT GROUP
SaintBear
🇷🇺Russia-attributed
15
aliases
Last seen:May 20, 2026
Intelligence Profile
A group targeting UA state organizations using the GraphSteel and GrimPlant malware.
Threat Analysis
SaintBear is a known-sophistication threat actor attributed to Russia, engaged in cyber operations with a primary motivation of unknown activity patterns.
External References
Quick Facts
TypeAPT / Threat Group
Origin🇷🇺 Russia
Aliases15
SourceMalpedia
Also Known As
UAC-0056NodariaNascent UrsaEMBER BEARStorm-0587UNC2589SaintBearLorec53Lorec BearDEV-0587Cadet BlizzardSaint BearTA471Bleeding BearFROZENVISTA
Research Links
Data sourced from Malpedia, Ransomware.live, RansomLook, and CTIWATCH OSINT collection. Actor attribution is based on available intelligence and may be incomplete.