SaintBot is a Windows malware family used in spear-phishing campaigns primarily targeting Ukrainian organizations, including government and critical infrastructure entities, with related activity also observed against a Western government presence in Ukraine and targets in Georgia. It has been associated with the UAC-0056 intrusion set, also tracked as TA471 and SaintBear, a cluster widely linked to Russia-aligned activity.
SaintBot has been described as a downloader or multi-stage .NET loader that is commonly deployed after initial infection components such as OutSteel. Campaigns delivering SaintBot have used themed lures impersonating Ukrainian government bodies, including the National Health Service of Ukraine and the National Police of Ukraine. Observed delivery chains relied on spear-phishing emails carrying malicious documents, shortcut files, or embedded scripts that launched PowerShell to retrieve and execute follow-on payloads, often via legitimate public hosting services.
Once executed, SaintBot performs host and anti-analysis checks, including sandbox or virtual-machine detection and locale-based filtering. Reported samples avoid continued execution on systems configured for several post-Soviet locales, including Russia and Ukraine. The malware collects system information from infected hosts, encodes and encrypts the data, and sends it to command-and-control infrastructure over HTTP POST requests. SaintBot also supports persistence and post-compromise payload delivery. Reported capabilities include establishing autorun persistence, downloading and executing additional payloads, loading executables or DLLs directly in memory, process injection, self-update, and self-removal. Some analyses also documented attempted User Account Control bypass via Fodhelper on Windows 10.
In observed operations, SaintBot functioned as part of a broader espionage-oriented toolchain focused on intelligence collection and follow-on access rather than standalone destructive effects. Its repeated use alongside document-stealing malware and its targeting of Ukrainian state and strategic sectors indicate a role in sustained post-compromise access and modular payload deployment.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Even the Word documents attached to emails have used a variety of techniques, including malicious macros, embedded JavaScript and the exploitation of CVE-2017-11882 to install payloads onto the system." Also: "!!! COVID-21.doc ... Delivery document exploits CVE-2017-11882 to download www.baiden00[.]ru/win21st.txt"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
...а також завантажить і виконає шкідливу програму SaintBot (дата компіляції: 30.04.2021).
"...would download and install a payload known as SaintBot (a downloader) and OutSteel (a document stealer)."
14 distinct techniques documented for this family, organized by ATT&CK tactic.
In January 2022, there were reports of a series of cyberattacks that started from spear-phishing emails disguised as messages from the National Healthcare Service of Ukraine.
223 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool referenced as an alternate name associated with Storm-0587 in Microsoft's naming table.
Malware delivered via spear-phishing that performs UAC bypass, collects host information, encodes it, and sends it to C2 servers.
Multi-stage .NET malware loader/downloader used for persistent access and to fetch/execute additional payloads. Uses anti-analysis/locale checks, process injection (e.g., into MSBuild.exe and dfrgui.exe), UAC bypass via fodhelper.exe, persistence via Run key, and C2 command handling (execute payloads, load DLL in-memory, update, uninstall).
Downloader mentioned in a related resource about spear-phishing attacks targeting organizations in Ukraine.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.