SaintBear__2022__nsfocus_Lorec53-LoriBear-Ukraine_02-16-2022.pdf
ID: 72e9b04e-f311-46fc-8df9-2c3e3590edf9
STIX ID: report--72e9b04e-f311-46fc-8df9-2c3e3590edf9
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2022-02-18
Last Modified Date: 2022-02-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NSFOCUS Fuying Lab analyzes Lorec53 (Lori Bear) APT activity against Ukraine from late 2021 to February 2022, detailing large-scale phishing campaigns distributing Lorec53 malware (LorecDocStealer/OutSteel, LorecCPL, SaintBot) via decoy documents, lnk shortcuts, and weaponized PDFs/Word documents, with multiple download domains and targeted Ukrainian government and state entities.
