Space Pirates: Raiders of Privacy | Denis Kuvshinov

Опубликовано: 23 Сентябрь 2026
на канале: Kaspersky Tech
148
2

In this talk, we will delve into the Space Pirates cybercrime group, discovered by Positive Technologies ESC in late 2019 that has been active at least since 2017. The first extensive report on them emerged in early 2022. Recently, the group attacks on Russian firms, employing familiar tactics while refining their tools. Their primary objectives remain espionage and data theft, but they’ve broadened targets and geographic scope. In the past year, they targeted 16 organizations in Russia and one in Serbia, including government entities, educational institutions, security firms, aerospace manufacturers, and more. Deed RAT featured prominently in every investigation, indicating a shift away from other backdoors. Its code similarities with ShadowPad suggest an evolutionary link, with Deed RAT being exclusive to Space Pirates. It’s actively developed, evidenced by a 64-bit version discovered. We also encountered a distinct malware, Voidoor, delivered through Deed RAT. It utilized legitimate resources Github and Voidtools.com as C&C servers.
Analysis of login events led us to attribute Voidoor to the Space Pirates group.

#SAS2023 #SpacePirates #SpacePiratesAPT #Kaspersky