logo

SaintBear__2022__nsfocus_Lorec53-LoriBear-Ukraine_02-16-2022.pdf

ID: 72e9b04e-f311-46fc-8df9-2c3e3590edf9

STIX ID: report--72e9b04e-f311-46fc-8df9-2c3e3590edf9

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2022-02-18

Last Modified Date: 2022-02-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
NSFOCUS Fuying Lab analyzes Lorec53 (Lori Bear) APT activity against Ukraine from late 2021 to February 2022, detailing large-scale phishing campaigns distributing Lorec53 malware (LorecDocStealer/OutSteel, LorecCPL, SaintBot) via decoy documents, lnk shortcuts, and weaponized PDFs/Word documents, with multiple download domains and targeted Ukrainian government and state entities.