🇷🇺Berserk Bear
🇷🇺 Berserk Bear is a tracked threat actor in the Clankerusecase corpus. Attributed to RU. Primary motivation: State. We map 26 detection use cases to this actor across 77 MITRE ATT&CK techniques, with 1 threat-intel article citing them. Active in our corpus from 2026-05-22 to 2026-05-22.
crit 1
26Use cases
1Articles
77Techniques
45IOCs
Known aliases
Berserk BearEnergetic BearDragonFlyCrouching YetiIron LibertyDragonflyTEMP.IsotopeDYMALLOYTG-4192IRON LIBERTYGhost BlizzardBROMINE
Top techniques
All other tracked techniques
T1003.002 · Security Account ManagerT1003.003 · NTDST1003.004 · LSA SecretsT1005 · Data from Local SystemT1006 · Direct Volume AccessT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1033 · System Owner/User DiscoveryT1036.008 · Masquerade File TypeT1036.010 · Masquerade Account NameT1053.005 · Scheduled TaskT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.006 · PythonT1069.002 · Domain GroupsT1070.004 · File DeletionT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.002 · File Transfer ProtocolsT1071.004 · DNST1074.001 · Local Data StagingT1078 · Valid AccountsT1083 · File and Directory DiscoveryT1087.002 · Domain AccountT1090.001 · Internal ProxyT1098.007 · Additional Local or Domain GroupsT1105 · Ingress Tool TransferT1110 · Brute ForceT1110.002 · Password CrackingT1112 · Modify RegistryT1113 · Screen CaptureT1114.002 · Remote Email CollectionT1133 · External Remote ServicesT1135 · Network Share DiscoveryT1136.001 · Local AccountT1187 · Forced AuthenticationT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1210 · Exploitation of Remote ServicesT1218 · System Binary Proxy ExecutionT1219 · Remote Access ToolsT1221 · Template InjectionT1505.003 · Web ShellT1547.001 · Registry Run Keys / Startup FolderT1547.014 · Active SetupT1555.003 · Credentials from Web BrowsersT1558.003 · KerberoastingT1560 · Archive Collected DataT1562.001 · T1562.001T1564.001 · Hidden Files and DirectoriesT1564.002 · Hidden UsersT1566 · PhishingT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1572 · Protocol TunnelingT1583.001 · DomainsT1583.003 · Virtual Private ServerT1584.004 · ServerT1588.002 · ToolT1591.002 · Business RelationshipsT1595.002 · Vulnerability ScanningT1598.002 · Spearphishing AttachmentT1598.003 · Spearphishing LinkT1608.004 · Drive-by TargetT1685.005 · Clear Windows Event LogsT1686 · Disable or Modify System Firewall
Detection use cases (26)
Berserk Bear ICS reconnaissance: outlook.exe → LOLBin SMB enumeration of file shares Berserk Bear SMB credential-theft via forced authentication (T1187) to attacker-controlled responder PowerShell-parented taskkill of winrar.exe (Cloud Atlas LNK anti-forensic cleanup) PowerShower dropped to user Pictures folder as googleearth.ps1 SAM/SECURITY registry hives copied from VSS shadow to Public\Documents as .pdf termsrv.dll patched (multi-RDP enabling) - takeown + binary write + TermService restart OpenSSH reverse port-forward (-R) launched on a workstation - Cloud Atlas backup C2 Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Asset exposure — vulnerability matches article CVE(s) Phishing-link click correlated to endpoint execution Email attachment opened from external sender Office app spawning script/LOLBin child process Remote service execution — PsExec / SMB lateral movement 1Password failed sign-in burst 1Password impossible-travel sign-in Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public EgressThreat-intel articles (1)
Tracked indicators
Domains (26)
agenciakharis.com.br allgoodsdirect.com.au alnakhlah.com.sa amerikastaj.com bigbang.me cloudguide.in firsai.tipshub.net fishingflytackle.com goverru.com humanitas.si internationalcommodities investika-club.com istochnik.org kommando.live kufar.org lafortunaitalian.co.uk landscapeuganda.com mamurjor.com onedrivesupport.net paleturquoise-dragonfly- spbnews.net tenkoff.org totallegacy.org ultimatecore.net wizzifi.com +1 moreIP addresses (19)
146.70.53.171 185.126.239.77 185.22.154.73 185.250.181.207 185.53.179.136 194.102.104.207 194.87.196.163 195.58.49.9 37.228.129.224 45.15.65.134 45.87.219.116 46.17.44.125 46.17.44.212 46.17.45.49 46.17.45.56 5.181.21.75 81.30.105.71 93.125.114.193 93.125.114.57CVEs (1)
CVE-2018-0802