Space Pirates
Space Pirates is a China-linked espionage threat cluster named by Positive Technologies (PT ESC), which stated it could not unambiguously link the activity to a previously known group and therefore assigned the new name “Space Pirates.” PT ESC reported the group has been active since at least 2017 and primarily targets government institutions and organizations in the aerospace, IT, and electric power sectors in Russia, Georgia, and Mongolia. PT ESC also noted some attacks against Chinese financial services companies, suggesting possible financial motivation in addition to espionage. At least two intrusions against Russian organizations were reported as successful, including long-term persistence, compromise of at least 20 servers in one case, theft of more than 1,500 internal documents, and access to employee account information. According to PT ESC, Space Pirates’ malware arsenal includes unique or cluster-specific families such as MyKLoadClient, BH_A006, and Deed RAT, as well as Zupdax, PlugX, ShadowPad, Poison Ivy, a modified PcShare variant referred to as RtlShare, ReVBShell, and dog-tunnel. Reported tradecraft includes spearphishing, SFX archives, DLL side-loading, reflective loading, UAC bypass, COM hijacking, modular plugin architectures, custom encrypted or encoded command-and-control protocols, use of signed binaries, and use of stolen certificates. PT ESC described core infrastructure as relying on a small number of IP addresses referenced by DDNS domains, including deeply nested subdomains. PT ESC assessed the actor as likely of Asian, probably Chinese-speaking, origin based on Chinese-language artifacts, PDB paths, and tooling. Multiple sources in the provided content explicitly describe Space Pirates as China-based or China-linked. However, the content also states that attribution is complicated by extensive tool sharing and operational overlap with other China-nexus clusters, including Winnti/APT41, Bronze Union/APT27, TA428, RedFoxtrot, Mustang Panda, Night Dragon-linked activity, FishMonger (Aquatic Panda), SixLittleMonkeys, Kelp/Salt Typhoon, and Earth Longzhi. PT ESC highlighted especially strong overlap with TA428 and Bronze Union/APT27, including shared infrastructure, malware-loading chains, and overlap in the Able Desktop supply-chain compromise context. The content also notes that Webworm overlaps with FishMonger, SixLittleMonkeys, and Space Pirates, and that UnsolicitedBooker showed tactical overlaps with Space Pirates. The content further states that a malicious DLL used in a 2025 China-linked intrusion had previously been used in attacks linked to Space Pirates, and that DLL sideloading via the legitimate VipreAV component vetysafe.exe loading sbamres.dll is among techniques associated with activity overlapping Space Pirates.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Software & Services
- Capital Goods
- Utilities
- Financial Services
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
- 🇬🇪 Georgia
- 🇲🇳 Mongolia
- 🇨🇳 China
Tradecraft
61 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
23 malware families attributed to this actor across reporting.
18 additional families tracked in Mallory.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
Privilege Escalation T1068 Exploitation for Privilege Escalation Группа Space Pirates может использовать уязвимость CVE-2017-0213 для повышения привилегий
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
Observables
533 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
China-nexus activity cluster noted as overlapping with Webworm.
Referenced as a separate activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
Referenced as an activity cluster with tactical overlaps to UnsolicitedBooker; no additional operational details provided in this content.
China-linked actor referenced in connection with prior use of a malicious DLL (sbamres.dll) and DLL sideloading-style tradecraft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.