Summary:
The Space Pirates Advanced Persistent Threat (APT) group has escalated its cyber-attacks against Russian organizations, exhibiting an alarming surge in activity. The group employs new and sophisticated malware, such as the Voidoor backdoor and the Deed RAT, while targeting a broader range of sectors. Their primary objectives remain espionage and data theft, compromising at least 16 organizations in Russia and one in Serbia, including government institutions, educational facilities, security firms, aerospace, and more.[/subscribe_to_unlock_form]
Summary:
The Space Pirates Advanced Persistent Threat (APT) group has escalated its cyber-attacks against Russian organizations, exhibiting an alarming surge in activity. The group employs new and sophisticated malware, such as the Voidoor backdoor and the Deed RAT, while targeting a broader range of sectors. Their primary objectives remain espionage and data theft, compromising at least 16 organizations in Russia and one in Serbia, including government institutions, educational facilities, security firms, aerospace, and more.[emaillocker id="1283"]
Discovered during an investigation, Voidoor is a 32-bit EXE file, appearing to be delivered via the Deed RAT already present on the victim's computer. Voidoor exhibits a multi-stage process for communication and persistence. It interacts with GitHub repositories, utilizing personal access tokens to communicate and obtain commands. Upon execution, Voidoor creates an invisible window with two threads, one of which stays idle for ten hours before terminating the main thread. Through the use of voidtools forum, the malware communicates through private messages, setting up rules to receive commands for further actions. Deed RAT is a prominent backdoor observed in almost every attack conducted by Space Pirates. It appears to be an evolution of ShadowPad and PlugX but has only been associated with this APT group. Recent developments include a 64-bit version, changes in string decryption algorithms, and the addition of two new plugins: Disk and Portmap. The malware continues to use the Google Public DNS, Cloudflare DNS, Quad9 DNS, and possibly Cisco OpenDNS for name resolution.
The Space Pirates APT group poses a significant threat to Russian organizations, employing sophisticated tactics and malware to achieve their espionage objectives. Their use of public tools like Acunetix for reconnaissance complicates detection. Organizations must strengthen their cybersecurity defenses, including regular threat intelligence monitoring, vulnerability assessments, and employee training. Collaboration between sectors is crucial to share threat intelligence and mount a unified defense against the evolving tactics of Space Pirates APT. Understanding the execution process of their malware is vital in developing effective defense strategies and mitigating the risk posed by this persistent threat.
Threat Profile:

References:
The following reports contain further technical details:
[/emaillocker]