Netskope Threat Labs

Waterbear

ATP Sandbox Adv. Heuristics

Waterbear is modular malware attributed to the BlackTech threat actor, used primarily for lateral movement and for decrypting and triggering payloads on compromised networks. It is also capable of hiding its network behaviors from defenders.

First seen
April 2022
Last seen
September 2026

14 techniques across 5 tactics.

TA0002 Execution

TA0005 Stealth

TA0007 Discovery

TA0011 Command and Control

  • T1105Ingress Tool Transfer

TA0112 Defense Impairment

Alert Name
Win32.Backdoor.Waterbear
Win32.Trojan.Waterbear