← Threat Actors / Russia / DEV-0586
DOSSIER // DEV-0586

DEV-0586

▲ High Threat Russia
Primary Aliases: Bleeding Bear Cadet Blizzard DEV-0587 Ember Bear
Primary Motivation Sabotage
Confidence Rating 70% (Grounded)

MSTIC has not found any notable associations between this observed activity, tracked as DEV-0586, and other known activity groups. MSTIC assesses that the malware (WhisperGate), which is designed to look like ransomware but lacking a ransom recovery mechanism, is intended to be destructive and designed to render targeted devices inoperable rather than to obtain a ransom.

🎯 Target Sectors & Focus

Defense & Aerospace Government & Diplomacy Financial & Crypto Critical Infrastructure

🛡️ MITRE ATT&CK® Attack Lifecycle (47 TTPs)

📥 Download Navigator JSON
Persistence & Privilege Escalation 2
Defense Evasion 1

📰 Verified Campaigns & Intelligence Archive

🔔 Subscribe to Alerts
Copied to clipboard

LINK COPIED TO CLIPBOARD