OutSteel, also known as LorecDocStealer, is an AutoIt-based document stealer and file uploader targeting Windows systems. It automatically searches compromised computers for files matching a predefined set of extensions, collects potentially sensitive documents, and uploads them to a hardcoded command-and-control destination using HTTP POST requests. OutSteel can also download and execute SaintBot, extending the infection chain with an additional downloader.
OutSteel is associated with Ember Bear, also tracked as UAC-0056 and Saint Bear, and has been deployed in spearphishing campaigns targeting Ukrainian government organizations and the energy sector. Delivery mechanisms include malicious email attachments and links to hosted archives containing lure documents and shortcut files. Other campaigns use password-protected Microsoft Word documents with embedded JavaScript objects. Victim interaction triggers JavaScript or PowerShell execution that retrieves and launches the malware. Observed lures impersonate Ukrainian health authorities and law enforcement, and Discord infrastructure has been abused to host archives and executable payloads.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Even the Word documents attached to emails have used a variety of techniques, including malicious macros, embedded JavaScript and the exploitation of CVE-2017-11882 to install payloads onto the system." Also: "!!! COVID-21.doc ... Delivery document exploits CVE-2017-11882 to download www.baiden00[.]ru/win21st.txt"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OutSteel is a file uploader and document stealer developed with the scripting language AutoIT.
"The OutSteel tool is a simple document stealer. It searches for potentially sensitive documents based on their file type and uploads the files to a remote server."
23 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2022, there were reports of a series of cyberattacks that started from spear-phishing emails disguised as messages from the National Healthcare Service of Ukraine.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, enumerating PIDs, checking for specific process names, or using APIs such as CreateToolhelp32Snapshot and commands such as tasklist and ps.
257 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AutoIt-based document stealer delivered through spear-phishing and multistage loaders, including BabaDeda. It searches for files with selected extensions and uploads them to a hardcoded command-and-control endpoint. It was deployed alongside SaintBot in an attack against a Ukrainian energy organization.
Downloader malware used as an intermediate stage to fetch and execute SaintBot.
A trojan delivered via an embedded object in a malicious .docx document; the embedded JavaScript writes to the Temp directory, runs via wscript, downloads a payload from Discord CDN as GoogleChromeUpdate.exe, and executes it with Start-Process.
AutoIT-based document stealer/file uploader that enumerates files by extension (Office docs, archives, email data like PST, databases) and exfiltrates them to a hardcoded C2 endpoint (e.g., /upld/). Can also download/execute a secondary payload (SaintBot) from a secondary C2.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.