OutSteel — Malware Profile
OutSteel is a file uploader and document stealer developed with the scripting language AutoIT that has been used by Saint Bear since at least March 2021.
MITRE ATT&CK techniques (17)
- T1005 Data from Local System
- T1020 Automated Exfiltration
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1057 Process Discovery
- T1059.003 Windows Command Shell
- T1059.010 AutoHotKey & AutoIT
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1119 Automated Collection
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1570 Lateral Tool Transfer