Space Pirates is a long-running China-linked cyber-espionage cluster active since at least 2017. The group has primarily targeted government institutions and organizations in the aerospace, information technology, and electric power sectors, with a strong concentration on Russia and additional victimology in Georgia and Mongolia. Reporting also notes some targeting of Chinese financial companies, suggesting occasional financially oriented activity, but espionage and theft of confidential information remain the dominant objectives. The cluster was named from the recurring string “P1Rat” found in development artifacts and from its aerospace-focused targeting. It is assessed to have Asian, likely Chinese-speaking, origins based on Chinese-language artifacts, tooling, and repeated tactical overlap with other China-nexus activity. Attribution to a specific named Chinese state cluster remains unresolved because of extensive tool sharing and operational intersections with groups tracked as APT41/Winnti, Bronze Union/APT27, TA428, RedFoxtrot, Mustang Panda, Night Dragon-linked activity, FishMonger, Aquatic Panda, SixLittleMonkeys, and Webworm. Space Pirates has used a diverse malware arsenal that includes group-associated families such as MyKLoadClient, BH_A006, and Deed RAT, alongside widely shared Chinese ecosystem tools including ShadowPad, PlugX, Poison Ivy, a modified PcShare variant referred to as RtlShare, Zupdax, and public utilities such as ReVBShell and dog-tunnel. Deed RAT has been repeatedly associated with the cluster, and later malware lineage analysis has linked BloodAlchemy to Deed RAT as an evolutionary descendant within the broader ShadowPad-related ecosystem. Observed intrusion chains include spearphishing with malicious documents, use of Royal Road-built lures, DLL sideloading, reflective or in-memory loading, scheduled-task persistence, COM hijacking, UAC bypass, process injection, proxying and tunneling, and long-term post-compromise operations. In successful intrusions, the group maintained persistence for many months, moved across numerous hosts and servers, stole large volumes of internal documents, and obtained employee account information. Malware attributed to the cluster supports remote shell access, file transfer, disk operations, proxying, configuration updates, persistence management, victim reconnaissance, and exfiltration. Space Pirates is best understood as a China-linked espionage actor embedded in a broader ecosystem of shared malware, loaders, and infrastructure. Its operations emphasize stealthy persistence, modular backdoors, and sustained intelligence collection against state and strategic-sector targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
533 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster noted as overlapping with Webworm.
Referenced as a separate activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
Referenced as an activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
China-linked actor referenced in connection with prior use of a malicious DLL (sbamres.dll) and DLL sideloading-style tradecraft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.