Quick Summary
AllegedExecutive Summary
SpaceBears ransomware actors have listed StellarRAD Systems, a technology company based in the United States, on their dark web portal. The listing occurred on July 29, 2026, and SOCRadar’s Dark Web Monitoring service identified it. The evidence cited for the listing includes two harvested credentials associated with StellarRAD Systems’ remote-access infrastructure. Given that SpaceBears has claimed a relatively small number of victims in the preceding two months, each new listing provides additional insight into the group’s current operational focus and targeting patterns. StellarRAD Systems operates within the technology sector, an industry frequently targeted by ransomware operations. In the 60 days leading up to this listing, SpaceBears had claimed approximately eight other victims. Historically, the group has predominantly targeted the manufacturing, technology, and energy sectors, with a significant concentration of victims in Germany, Cameroon, and Poland. Previous victims whose profiles share similarities with StellarRAD Systems, such as being technology companies or US-based organizations, include Turbosoft, Techpol-System, Salters propane, and Cattani. StellarRAD Systems aligns with the group’s typical sector targeting. However, its US location deviates from SpaceBears’ recent trend of focusing on continental Europe. This geographical outlier suggests that the targeting of StellarRAD Systems may be more driven by sectorial interest rather than a regional campaign.
Technical Analysis
SOCRadar’s analysis of stealer-log telemetry has revealed a significant credential exposure related to the stellarrad[.]com domain. Specifically, two records were identified pointing to internal authentication services within StellarRAD Systems’ own infrastructure. These credentials pertain to a Cisco AnyConnect VPN gateway, which serves as the primary remote access entry point for employees to connect to the internal network, and an internet-facing file-transfer service. Both sets of credentials were classified as belonging to employees or service accounts on organization-owned systems, distinct from customer accounts. The absence of corporate user credentials on third-party services within this particular data slice indicates a risk profile leaning towards corporate network intrusion rather than widespread consumer-level compromise. The captured logs were dated within a single month, specifically from late February to late March 2026, with ingestion timestamps closely mirroring the log dates, suggesting recent and active credential harvesting. Importantly, neither of the identified credentials shows any indication of rotation within the queried timeframe. While the queried data sample did not contain records for other stellarrad[.]com subdomains, such as mail or identity portals, this does not preclude the possibility of their exposure. The exposure of credentials for a VPN gateway and a file-transfer service presents a direct pathway for threat actors. For ransomware groups like SpaceBears, the exploitation of infostealer-harvested credentials is a common initial access vector. Threat actors or initial access brokers often procure recent logs from underground marketplaces, validate the corporate credentials, and then use them to gain unauthorized access to systems such as Microsoft 365, VPNs, or remote-access portals, ultimately leading to ransomware deployment. While this evidence does not definitively confirm that SpaceBears specifically utilized these credentials, the presence of a remote-access gateway credential is a valuable asset for an access broker. This pattern aligns closely with the typical intrusion kill chain observed in similar incidents. Therefore, the identified exposure should be treated as an operational hypothesis to be validated against authentication telemetry, rather than a confirmed attribution of the attack to SpaceBears. The immediate recommended actions include continued monitoring of dark web and stealer logs, a thorough review of authentication telemetry for VPN and file-transfer service access, and proactive credential hygiene checks.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.