Uptime Hamster: 21d 11h 22mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21
Logo del actor de amenaza Boulder Bear

Boulder Bear

0 incidentes 0 paises 0 sectores apt RU Ultimo: -
Ver en IntelTracker → APTTrail →
Boulder Bear is a cyber espionage threat actor believed to operate from Eastern Europe, with a suspected state sponsorship from Russia. This group specializes in intelligence gathering against government and defense sectors, demonstrating a consistent application of advanced persistent threat tactics. Boulder Bear gains initial access through complex spear-phishing campaigns and by exploiting zero-day vulnerabilities. The group maintains a highly organized operational structure focused on intelligence collection and rapid adaptation to security measures. While information about this specific designation, reportedly used by CrowdStrike, remains limited in public reporting, its operations are characterized by obfuscation and the use of remote access tools.

Actores similares

energetic-bearactor · 1ember-bearactor · 1APT29 (Cozy Bear)actor · 1Saint Bearthreat-actor · 1Energetic Bearapt · 0Pat Bearapt · 0White Bearapt · 0Ember Bearthreat-actor · 0spacebearsthreat-actor · 29space-bearsactor · 12
Tecnicas MITRE
T1027 - Obfuscated Files or Information, T1071.001 - Web Protocols, T1078, T1055 - Process Injection, T1105 - Ingress Tool Transfer, T1059
Tipo
apt
Pais origen
RU
Motivacion
-
Impacto
7
Actualizado
Wed, 01 Ju