OutSteel is a Windows document-stealing malware family written in AutoIt and associated with phishing operations targeting Ukrainian organizations, particularly government entities. It has been linked to activity tracked as UAC-0056 and to the threat actor commonly referred to as Saint Bear. OutSteel is typically delivered through spearphishing emails impersonating Ukrainian government institutions, including the National Health Service of Ukraine and the National Police of Ukraine. Observed lures have included malicious attachments, password-protected documents, embedded objects in Office files, shortcut files, and links to archives hosted on public file-sharing infrastructure. Execution chains have used PowerShell, Windows Script Host, and embedded JavaScript to retrieve and launch the malware.
Its primary function is automated collection and theft of files from compromised hosts. OutSteel searches local systems for documents matching predefined file-extension criteria, gathers potentially sensitive files, and uploads them to remote command-and-control infrastructure, including via HTTP POST requests over its C2 channel. It has also been observed collecting host information. In documented campaigns, OutSteel additionally acted as a staging component by downloading and executing SaintBot as a follow-on payload.
The malware has been used in targeted intrusion activity during the Russia-Ukraine conflict and is notable for straightforward but effective document theft tradecraft centered on socially engineered delivery and rapid exfiltration of victim files.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Even the Word documents attached to emails have used a variety of techniques, including malicious macros, embedded JavaScript and the exploitation of CVE-2017-11882 to install payloads onto the system." Also: "!!! COVID-21.doc ... Delivery document exploits CVE-2017-11882 to download www.baiden00[.]ru/win21st.txt"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...призведе до завантаження і запуску шкідливої програми OutSteel (дата компіляції: 28.01.2022). Остання забезпечить пошук та викрадення документів на комп’ютері жертви... OutSteel – шкідлива програма, розроблена з використанням мови програмування AutoIt; основний функціонал – викрадення файлів за визначеним переліком розширень файлів...
"The OutSteel tool is a simple document stealer. It searches for potentially sensitive documents based on their file type and uploads the files to a remote server."
21 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2022, there were reports of a series of cyberattacks that started from spear-phishing emails disguised as messages from the National Healthcare Service of Ukraine.
wscript.exe powershell.exe "%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\powershell.exe"
у випадку відкриття яких на комп’ютері жертви буде виконано powershell-команду, що, в свою чергу, призведе до завантаження і запуску шкідливої програми OutSteel
створення і запуску на комп’ютері Javascript-файлу, наприклад «GSU207@POLICE.GOV.UA - Повідомлення (2).js»
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Остання забезпечить пошук та викрадення документів на комп’ютері жертви
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
257 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
29 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Downloader malware used as an intermediate stage to fetch and execute SaintBot.
A trojan delivered via an embedded object in a malicious .docx document; the embedded JavaScript writes to the Temp directory, runs via wscript, downloads a payload from Discord CDN as GoogleChromeUpdate.exe, and executes it with Start-Process.
AutoIT-based document stealer/file uploader that enumerates files by extension (Office docs, archives, email data like PST, databases) and exfiltrates them to a hardcoded C2 endpoint (e.g., /upld/). Can also download/execute a secondary payload (SaintBot) from a secondary C2.
Document stealer mentioned in a related resource about spear-phishing attacks targeting organizations in Ukraine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.