Space Pirates intrusions at Russian aerospace enterprises (disclosed 2022)
What happened
Positive Technologies' expert security centre named the Space Pirates group after the P1Rat string in the PDB paths of its malware and after its targeting of the aerospace industry. The research traces activity to no later than 2017 and begins with a phishing email aimed at a Russian aerospace enterprise at the end of 2019 that carried a link to then-unknown malware; the same malware turned up in 2020 during an incident response at a Russian government agency, and the investigation from there uncovered several malware families sharing network infrastructure. Confirmed targets are Russian aerospace enterprises, government agencies and energy companies, plus organisations in Georgia and Mongolia. Two Russian compromises are described as successful: one in which the actor held access for about ten months across more than twenty servers and took over 1,500 documents, and another lasting more than a year across twelve corporate nodes in three regions. The toolset combines unique implants (Deed RAT, MyKLoadClient, BH_A006) with widely shared ones (PlugX, ShadowPad, Poison Ivy, modified PcShare, ReVBShell). Attribution is to an Asian, Chinese-language nexus with documented overlaps with Winnti/APT41, Bronze Union/APT27, TA428, RedFoxtrot, Mustang Panda and Night Dragon, and the researchers state that Space Pirates and TA428 may share tools, network resources and access to infected systems, which they treat as a limit on attribution rather than a conclusion.
The technical account is detailed and the dwell times and document count are specific, but the connection between the specific numbers and the specific victims is not made: the research reports two successful Russian compromises and a victim list, and does not tie the 1,500 documents to the aerospace enterprise. The single edge is scoped to reflect that. The vendor is Russian and the victims are Russian, which is worth stating for the reader but does not by itself weaken the malware analysis. The English research page carries a 2024 publication date although the research was covered in the trade press in May 2022; the sources file records both dates rather than picking one silently. SCOPE UNDETERMINED, recorded 2026-08-23. Whether this record belongs in this corpus has not been established. A record is admitted here when a space system, meaning a spacecraft, a mission ground segment, a tracking or command path or a launch system, is in the attack path; the victim being a space-sector organisation is expressly not the test. What the sources establish is three separate Russian victims described in three separate ways, and no victim named. Positive Technologies reports that "At least two attacks on Russian organizations can be considered successful", the first reaching "at least 20 servers on the corporate network" over about ten months and the second installing malware "on at least 12 corporate nodes in three different regions". It never says which of its victims those two were. Separately it reports that "In the summer of 2021, PT ESC revealed traces of compromise of another Russian aerospace enterprise" and that "we found connections to the same network infrastructure on its computers", and says nothing whatever about what those computers were. What no cited source establishes is the estate at the aerospace victim. The word corporate belongs to the two anonymous compromises and cannot be carried across to the named-sector one, and "at least 20 servers" is a floor rather than an inventory. Neither source contains spacecraft, satellite, ground station, mission control, telemetry, telecommand, orbit or cosmodrome in any sense, but silence in a malware analysis that never describes an estate is weak evidence about it. A source placing a satellite control centre, a mission operations network, a telemetry or telecommand system, spacecraft integration and test equipment or launch ground support equipment at one of these enterprises would settle it one way, as would a source establishing that the more than 1,500 stolen documents were spacecraft design material and came from the aerospace victim; a source characterising that victim's compromised estate as ordinary corporate infrastructure would settle it the other. The record stays published while the question is open, under decisions entry 189.
Attack vector
Phishing email carrying a link to malware, in the first observed case aimed at a Russian aerospace enterprise at the end of 2019.
Operational impact
None reported in the space domain. No source describes an effect on a spacecraft, a mission or a ground system.
Data compromised
More than 1,500 documents in one of the two successful Russian compromises. The research does not state which victim that compromise was, so it is not established that the documents were the aerospace enterprise's.
Affected segments
supply_chain
Disclosed
2022-05-18
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
The group is named for its aerospace targeting, the earliest observed operation is a phishing email aimed at a Russian aerospace enterprise, and the campaign is characterised as espionage with a document haul in the thousands. REC-0001's objective is the design picture of spacecraft and their supporting ecosystem, which is the material an aerospace enterprise holds. Confidence is low, not moderate, for a specific reason: the research reports the 1,500-document theft as one of two successful Russian compromises without saying which victim it was, so the link between the aerospace targeting and the document haul is the reader's inference and not the source's statement.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
SPARTA's own citation. REC-0008 is the adversary mapping manufacturers, lots, test houses, custody handoffs, signing services and promotion gates to locate choke points where trust is assumed rather than verified. Nothing in the research describes that activity. The victims include aerospace enterprises; that makes them part of a supply chain, which is not the same as the chain being reconnoitred.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Space Pirates: analyzing the tools and connections of a new hacker groupVendor threat intelligence
Tier 2: The originating research, published by the vendor's expert security centre with the malware families, the dwell times and the infrastructure overlaps set out. The vendor is Russian and the victims are Russian, which is worth stating but does not by itself weaken the technical account.
Tier 3: Security trade outlet with a named reporter, summarising the vendor research. Its value here is that it is firmly dated, which fixes the research to May 2022 against the vendor page's later republication date.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.