Space Pirates, also known as Erudite Mogwai and Webworm, is a suspected China-nexus espionage threat actor that has been observed targeting Russian government and information technology organizations. The group has been linked to intrusions involving custom backdoors and shared tooling seen across multiple China-aligned clusters, indicating either operational collaboration or access to a common malware ecosystem. Operations attributed to Space Pirates have included deployment of the .NET backdoor LuckyStrike Agent, also referred to in some reporting as NetDraft or NosyDoor. This malware supports remote shell execution, file transfer, directory browsing, plugin execution, arbitrary .NET assembly execution, host profiling, and encrypted communications through Microsoft OneDrive using Microsoft Graph API, reflecting a modular post-compromise capability set oriented toward long-term access and intelligence collection. LuckyStrike Agent has also used AppDomain Manager Injection for stealthy execution inside legitimate .NET processes. The actor has additionally been associated with compromises of Russian public-sector infrastructure in which multiple implants were present, including ShadowPad-related tooling and a modular backdoor known as ShadowRelay. ShadowRelay is designed to establish persistence, load plugins on demand, operate in client or server mode, relay communications into segmented environments, evade analysis, and optionally inject into other processes. Its design suggests use in covert access maintenance and internal pivoting rather than as a standalone collection implant. Reported activity shows Space Pirates targeting Russian state and IT environments, with tradecraft including exploitation of vulnerable internet-facing services, persistence establishment, post-exploitation tooling, process injection, reconnaissance, and exfiltration via cloud-backed command channels. Malware and infrastructure overlaps with other China-aligned actors have led multiple researchers to note similarities between Space Pirates and clusters such as LongNosedGoblin, although they remain tracked separately due to differing tactics and operational patterns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with deploying the same NosyDoor/LuckyStrike Agent malware against Russian IT organizations.
Threat cluster reported using NetDraft against Russian IT organizations in 2024.
Named APT cluster reported present on a Russian organization’s network (per Rostelecom security team reporting).
Вероятная компрометация организации госсектора через уязвимый Microsoft Exchange; на зараженных системах обнаружен Shadowpad Light (Deed RAT).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.