Space Pirates
Space Pirates is a China-linked, likely Chinese-speaking cyber-espionage threat cluster first named by Positive Technologies. The group has been active since at least 2017 and primarily targets government institutions and organizations in the aerospace, IT, and electric power sectors, with victims identified in Russia, Georgia, and Mongolia. Reporting also notes related targeting of Russian organizations following the invasion of Ukraine, and some activity against Chinese financial companies. Positive Technologies assessed the group’s primary objectives as espionage and theft of confidential information; in successful intrusions, the actors maintained long-term persistence, compromised numerous hosts and servers, and stole more than 1,500 internal documents and employee account information. Space Pirates has been associated with spearphishing and phishing emails delivering malicious Office and RTF documents, including Royal Road-built lures and documents exploiting CVE-2018-0798. The group has used DLL side-loading, reflective loading, UAC bypass, COM hijacking, scheduled persistence, custom encrypted or encoded command-and-control protocols, signed binaries, and stolen certificates. Infrastructure has included DDNS-based command-and-control with deeply nested subdomains. Its malware arsenal includes group-specific or closely associated families such as MyKLoadClient, BH_A006, and Deed RAT, as well as Zupdax, PlugX, ShadowPad, Poison Ivy, a modified PcShare variant referred to as RtlShare, ReVBShell, dog-tunnel, and Bisonal RAT. MyKLoadClient has been delivered through spearphishing using SFX archives and DLL side-loading or via a custom dropper; it supports shell access, disk enumeration, file transfer, and proxying. Zupdax is described as a long-running backdoor used in related activity. Reporting also states that a malicious DLL used in later China-linked intrusions had previously been used in attacks linked to Space Pirates. Attribution remains complicated by tool sharing and operational overlap. Public reporting describes overlaps with TA428, Bronze Union/APT27, Winnti/APT41, RedFoxtrot, Mustang Panda, Night Dragon-linked activity, FishMonger (Aquatic Panda), SixLittleMonkeys, Kelp/Salt Typhoon, and Earth Longzhi. Positive Technologies highlighted especially strong overlap with TA428 and Bronze Union/APT27, while other reporting noted tactical overlap with China-aligned clusters including FishMonger, SixLittleMonkeys, and UnsolicitedBooker. Despite these overlaps, multiple sources describe Space Pirates itself as a China-based or China-linked threat actor.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
63 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
Observables
533 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster noted as overlapping with Webworm.
Referenced as a separate activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
Referenced as an activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
China-linked actor referenced in connection with prior use of a malicious DLL (sbamres.dll) and DLL sideloading-style tradecraft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.