Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
One of the stages of the BH_A006 malware is obfuscated using an unknown protector.
Space Pirates uses legitimate-looking names when creating services.
Space Pirates masks its malware as legitimate software.
Creating an svchost.exe process, and injecting the decompressed shellcode.
Space Pirates malware uses various algorithms to encrypt configuration data and payload.
73 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Multi-stage loader culminating in a Gh0st-derived backdoor payload. Uses layered droppers/loaders (overlay DLL reflective load; Sandboxie side-loading; encrypted .dat shellcode stages; repeated MemLoadLibrary-style reflective loading). Implements UAC bypass paths and persistence/service creation; includes a distinctive network signature generation algorithm (bit-level encoding with constant 0x31230C0). Shares shellcode/loader techniques with 9002 RAT samples.
Gh0st-derived backdoor delivered through a multilayer chain of compressed shellcode, reflective DLL loaders, UAC bypass components, service installation, and process injection. Uses a distinctive randomized network-signature algorithm. Related samples were present on VirusTotal in 2015.
Многостадийный загрузчик и бэкдор на основе модифицированного Gh0st, использующий несколько стадий шеллкода, обход UAC, side-loading и обфускацию для запуска полезной нагрузки.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.