Description
Waterbear is modular malware attributed to the BlackTech threat actor, used primarily for lateral movement and for decrypting and triggering payloads on compromised networks. It is also capable of hiding its network behaviors from defenders.
Stats
- First seen
- April 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
14 techniques across 5 tactics.
TA0002 Execution
- T1106Native API
TA0005 Stealth
TA0007 Discovery
TA0011 Command and Control
- T1105Ingress Tool Transfer
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Backdoor.Waterbear |
| Win32.Trojan.Waterbear |