Space Pirates is a China-linked cyberespionage threat cluster active since at least 2017. It targets government agencies and aerospace, information technology, and electric power organizations in Russia, Georgia, and Mongolia. Its malware has also been used against Chinese financial services companies. Its principal objectives are espionage and theft of confidential information; a specific state sponsor has not been established. The group conducts spearphishing using malicious attachments and links, including Royal Road-generated documents exploiting Microsoft Equation Editor vulnerabilities. Its toolkit includes MyKLoadClient, BH_A006, and Deed RAT, alongside Zupdax, RtlShare, PlugX, ShadowPad, Poison Ivy, ReVBShell, and dog-tunnel. Several of these tools are shared with other threat actors and are not reliable attribution markers in isolation. Deployment techniques include self-extracting archives, legitimate signed executables used for DLL sideloading, reflective loading, encrypted and compressed payloads, and process injection. Persistence mechanisms include registry autoruns, Windows services, and COM hijacking, while privilege escalation includes UAC bypass. Post-compromise activity includes domain enumeration, browser-password extraction, LSASS memory dumping, abuse of privileged domain accounts, and lateral movement through remote execution utilities. The operators collect documents into password-protected archives and use proxy and tunneling tools to support access. Confirmed Russian intrusions demonstrate prolonged persistence: one involved access to at least 20 servers for approximately ten months and theft of more than 1,500 internal documents and domain account information; another lasted more than a year and affected at least 12 corporate hosts. Space Pirates uses dynamic DNS-based command-and-control infrastructure and modular backdoors supporting remote command execution, file transfer, and proxying. Its activity has technical or infrastructure overlaps with TA428, APT41/Winnti, APT27/Bronze Union, RedFoxtrot, and other China-linked clusters. These overlaps do not establish that the groups are aliases or subgroups of Space Pirates.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
60 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
28 malware families attributed to this actor across reporting.
23 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
The report attributes initial intrusion to likely exploitation of CVE-2024-21893 and CVE-2024-21887. Files detected by Ivanti's Integrity Checker Tool matched filenames associated with LITTLELAMB, WOOLTEA, PITSOCK, and PITFUEL, and the observed evidence resembled previously reported attacks exploiting these vulnerabilities.
1 more CVE tied to this actor tracked in Mallory.
534 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster noted as overlapping with Webworm.
Referenced as a separate activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
Referenced as an activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
China-based group associated with Talisman and potentially MetaRAT through historical C2 infrastructure overlap. Identified as a possible operator of the campaign against Japanese shipping and transportation organizations, although no definitive campaign-specific infrastructure link was found. The report describes government agencies and telecommunications operators as principal targets of the three groups using Talisman, including Space Pirates, with activity concentrated in Central and South Asia.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.