OutSteel is a simple document-stealing malware family used to search compromised hosts for potentially sensitive files and exfiltrate them to a remote server over its command-and-control channel. Reported capabilities include automatically scanning for and collecting files with specific extensions, collecting information from a compromised host, uploading files over C2, and downloading and executing Saint Bot to a statically defined path intended to mimic a legitimate Windows process: %TEMP%\svjhost.exe. Observed delivery relies on user interaction via spearphishing, including malicious attachments and malicious links in spearphishing emails. Saint Bear has delivered malicious Microsoft Office documents containing an embedded JavaScript object that, when executed, downloads and runs OutSteel and Saint Bot. Based on the provided content, OutSteel is associated with Saint Bear and is used in phishing-driven intrusion activity to steal documents from victim systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
"Even the Word documents attached to emails have used a variety of techniques, including malicious macros, embedded JavaScript and the exploitation of CVE-2017-11882 to install payloads onto the system." Also: "!!! COVID-21.doc ... Delivery document exploits CVE-2017-11882 to download www.baiden00[.]ru/win21st.txt"
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Saint Bear has delivered malicious Microsoft Office files containing an embedded JavaScript object that would, on execution, download and execute OutSteel and Saint Bot.
"The OutSteel tool is a simple document stealer. It searches for potentially sensitive documents based on their file type and uploads the files to a remote server."
18 distinct techniques documented for this family, organized by ATT&CK tactic.
admin@338 has attempted to get victims to launch malicious Microsoft Word attachments delivered via spearphishing emails... APT28 attempted to get users to click on Microsoft Office attachments containing malicious macro scripts... Dragonfly has used various forms of spearphishing in attempts to get users to open malicious attachments.
Multiple actors and malware families are described as being delivered via spearphishing/phishing emails containing malicious links (e.g., APT28 used URL shorteners to redirect to credential harvesting sites; APT29 used links to ZIP files; APT33 used links to .hta files; BlackTech used links to cloud services; Wizard Spider used links to Google Drive/free file hosting). | APT29 used links to ZIP files containing malicious files; APT33 used links to .hta files; Leviathan used lookalike domains and stolen branding; Machete used links to external servers with ZIP/RAR archives; LazyScripter used links that redirect to download a malicious document; FIN8 used links to malicious documents with embedded macros.
During the 2016 Ukraine Electric Power Attack, Sandworm Team used the xp_cmdshell command in MS-SQL. During the 2025 Poland Wiper Attacks, the adversaries leveraged PsExec to run cmd.exe commands on multiple victim machines. Numerous malware families and groups are described as using cmd.exe, cmd /c, Windows command shell, or command-line interfaces to execute commands, payloads, reconnaissance, persistence, cleanup, and ransomware actions.
The content repeatedly describes victims being lured into opening malicious attachments, enabling macros, launching installers, clicking embedded files/links, or otherwise directly executing malicious content.
Sandworm Team leveraged Microsoft Office attachments which contained malicious macros that were automatically executed once the user permitted them... APT29 has used various forms of spearphishing attempting to get a user to open attachments... DarkGate is distributed through phishing links to VBS or MSI objects requiring user interaction for execution.
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
Confucius has used a file stealer to steal documents and images... Patchwork developed a file stealer to search C:\ and collect files with certain extensions... Winter Vivern delivered a PowerShell script capable of recursively scanning victim machines looking for various file types before exfiltrating identified files via HTTP.
Agrius used a custom tool, sql.net4.exe, to query SQL databases and then identify and extract personally identifiable information... AppleSeed has automatically collected data from USB drives, keystrokes, and screen images before exfiltration... Ember Bear engages in mass collection from compromised systems during intrusions.
ADVSTORESHELL exfiltrates data over the same channel used for C2... Agrius exfiltrated staged data using tools such as Putty and WinSCP, communicating with command and control servers... numerous malware and groups sent victim data, files, credentials, or host information over existing C2 channels.
233 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
AutoIT-based document stealer/file uploader that enumerates files by extension (Office docs, archives, email data like PST, databases) and exfiltrates them to a hardcoded C2 endpoint (e.g., /upld/). Can also download/execute a secondary payload (SaintBot) from a secondary C2.
Malware delivered via spearphishing attachments requiring user execution.
Malware downloaded and executed via embedded JavaScript objects in malicious Office files.
Scans for and collects files matching specific extensions.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.