SaintBear, Lorec53

Description

(NSFOCUS) In July 2021, several phishing documents created in Georgian were discovered by NSFOCUS Security Labs. In these phishing documents, the attackers used current political hotspots in Georgia to create bait and deliver a secret stealing Trojan to specifically targeted victims aiming to steal various documents from their computers. Correlation analysis shows that this phishing campaign and an earlier phishing attack against the Ukrainian government came from the same unknown threat entity, most likely composed of Russian hackers. From April to July of 2021, the group launched several phishing attacks applying a large number of network resources located in Russia. In order to facilitate ongoing tracking, NSFOCUS Security Labs has tentatively dubbed the hacker group Lorec53 by extracting special names from related Trojans.

Names

NameName-Giver
SaintBearThreatBook
Ember BearCrowdStrike
TA471Proofpoint
UNC2589FireEye
Lorec53NSFOCUS
UAC-0056CERT-UA
NodariaSymantec
FROZENVISTAGoogle
Storm-0587Microsoft
Nascent UrsaPalo Alto

Country

Motivation

  • Information theft and espionage

First Seen

2021

Observed Sectors

Observed Countries

Tools

Operations

Information

Mitre Attack

Playbook

Other Information

Uuid

8f37f59a-226c-4059-9222-c5ad769f31ef

Last Card Change

2024-03-10