SaintBot is a multistage Windows downloader used to establish persistent access and retrieve and execute additional malicious payloads. Its execution chain includes .NET components, sandbox and virtual-machine checks, locale-based execution restrictions, obfuscation, and process injection. It establishes persistence through a registry autorun mechanism and has been observed attempting to bypass User Account Control through abuse of the Windows Fodhelper utility. SaintBot collects host information, applies XOR and Base64 transformations, and transmits the resulting data to command-and-control infrastructure through HTTP POST requests. Supported commands include executing downloaded payloads, loading executables and DLLs in memory, updating itself on disk, and uninstalling.
SaintBot has been deployed in spear-phishing campaigns associated with UAC-0056, also tracked as Saint Bear, TA471, and Lorec53. Documented targets include Ukrainian government organizations and an energy organization in Ukraine. Delivery chains have used emails impersonating Ukrainian health-service or police authorities, malicious Word documents with embedded JavaScript, and archives containing lure documents and malicious shortcuts. These chains use PowerShell to download and execute intermediate payloads, including files hosted on Discord. SaintBot is frequently deployed alongside OutSteel, a separate document-stealing malware family that can download and execute SaintBot. Their roles are complementary: OutSteel performs document theft, while SaintBot supplies persistent payload-delivery and execution capabilities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Even the Word documents attached to emails have used a variety of techniques, including malicious macros, embedded JavaScript and the exploitation of CVE-2017-11882 to install payloads onto the system." Also: "!!! COVID-21.doc ... Delivery document exploits CVE-2017-11882 to download www.baiden00[.]ru/win21st.txt"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SaintBot malware was observed in a targeted email sent to an individual at an energy organization in Ukraine on Feb 1, 2022.
"...would download and install a payload known as SaintBot (a downloader) and OutSteel (a document stealer)."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2022, there were reports of a series of cyberattacks that started from spear-phishing emails disguised as messages from the National Healthcare Service of Ukraine.
223 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool referenced as an alternate name associated with Storm-0587 in Microsoft's naming table.
Actively developed downloader distributed through phishing attachments and multistage infection chains. It retrieves additional payloads, updates itself on disk, establishes startup persistence, and uses obfuscation, anti-analysis checks, and process injection. The reference describes deployments alongside OutSteel and a Defender-disabling executable.
Malware delivered via spear-phishing that performs UAC bypass, collects host information, encodes it, and sends it to C2 servers.
Multi-stage .NET malware loader/downloader used for persistent access and to fetch/execute additional payloads. Uses anti-analysis/locale checks, process injection (e.g., into MSBuild.exe and dfrgui.exe), UAC bypass via fodhelper.exe, persistence via Run key, and C2 command handling (execute payloads, load DLL in-memory, update, uninstall).
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.