Ember Bear

Russian Federation


EMBER BEAR is a Russia-based adversary assessed with moderate confidence to be attributable to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (Главное разведывательное управление, abbreviated to ГРУ/GRU). The adversary has conducted operations  against government and military organizations in Eastern Europe since early 2021, likely with the initial goal of ...

Community Identifiers



  • QvaD2TrSVdGby3LzPJKx6eF
  • 5bntK2TLfB
  • zk1W5ODeydUl


  • y2U4Fmd9R18MgSo

Contact our team about
IOCs for this adversary


During a cybersecurity incident, indicators of compromise (IoC) are clues and evidence of a data breach.