Researchers Expose Space Pirates’ Cyber Campaign Across Russia and Serbia

Teilen:

The threat actor known as Space Pirates has been linked to attacks against at least 16 organizations in Russia and Serbia over the past year by employing novel tactics and adding new cyber weapons to its arsenal.

The cybercriminals’ main goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks, Positive Technologies said in a deep dive report published last week.

Targets comprise government agencies, educational institutions, private security companies, aerospace manufacturers, agricultural producers, defense, energy, and healthcare firms in Russia and Serbia.

Space Pirates was first exposed by the Russian cybersecurity company in May 2022, highlighting its attacks on the aerospace sector in the nation. The group, believed to be active since at least late 2019, has links to another adversary tracked by Symantec as Webworm.

Positive Technologies’ analysis of the attack infrastructure has revealed the threat actor’s interest in harvesting PST email archives as well as making use of Deed RAT, a malware artifact exclusively attributed to the adversarial collective.

Deed RAT is said to be a successor to ShadowPad, which in itself is an evolution of PlugX, both of which are widely used by Chinese cyber espionage crews. Under active development, the malware comes in both 32- and 64-bit versions and is equipped to dynamically retrieve additional plug-ins from a remote server.

This includes a Disk plug-in to enumerate files and folders, execute commands, write arbitrary files to disk, and connect to network drives and a Portmap module that’s used for port forwarding.

Deed RAT also functions as a conduit to serve next-stage payloads such as Voidoor, a previously undocumented malware that’s is designed to contact a legitimate forum called Voidtools and a GitHub repository associated with a user named hasdhuahd for command-and-control (C2).

Voidtools is the developer of a freeware desktop search utility for Microsoft Windows called Everything, with its forum powered using an open-source forum software called MyBB. The primary goal of Voidoor is to login to the forum using hard-coded credentials and access the user’s personal messaging system to look for a folder matching a particular victim ID.

Evidence shows that the accounts on GitHub and voidtools were registered sometime in November 2022.

The hackers are working on new malware that implements unconventional techniques, such as Voidoor, and modifying their existing malware, Positive Technologies said, adding the actors use a large number of publicly available tools for navigating networks and leverage the Acunetix web vulnerability scanner to reconnoiter infrastructures it targets.

 

(c) Thin

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
17:03 Uhr, Juni 1, 2025
Wetter-Symbol 20°C
L: 19° | H: 21°
broken clouds
Luftfeuchtigkeit: 48 %
Druck: 1013 mb
Wind: 12 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 58%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:49 am
Sonnenuntergang: 9:07 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 21°°C 0 mm 0% 12 mph 64 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 21°°C 0 mm 0% 11 mph 84 % 1019 mb 0 mm/h
Di. Juni 03 10:00 pm
Wetter-Symbol
11° | 19°°C 1 mm 100% 16 mph 93 % 1014 mb 0 mm/h
Mi. Juni 04 10:00 pm
Wetter-Symbol
10° | 20°°C 0 mm 0% 13 mph 80 % 1010 mb 0 mm/h
Do. Juni 05 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 13 mph 95 % 1008 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 19°°C 0 mm 0% 12 mph 50 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
15° | 17°°C 0 mm 0% 8 mph 64 % 1014 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 84 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 79 % 1016 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 9 mph 72 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 51 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 35 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 7 mph 30 % 1017 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,314.30
0.15%
Ethereum(ETH)
€2,223.52
-0.55%
Fesseln(USDT)
€0.88
0.00%
XRP(XRP)
€1.89
-1.03%
Solana(SOL)
€135.90
-0.99%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.169123
-0.16%
Shiba Inu(SHIB)
€0.000011
2.36%
Pepe(PEPE)
€0.000011
0.67%
Peanut das Eichhörnchen(PNUT)
€0.231075
3.47%
Nach oben scrollen