Ransomware needs a way in. Stolen credentials are the cheapest one.
spacebears Ransomware Group
Ransomware group profile
Description
SpaceBears is a ransomware group that primarily focuses on high-profile cyberattacks across various industries. Known for employing sophisticated tactics, they utilize advanced encryption and double extortion methods while also operating as a data broker. Their operations have a global reach, making significant impacts on targeted organizations.
Key insights
- •Employs double extortion tactics by encrypting data and threatening to publish it online.
- •Targets a wide range of sectors, including healthcare and energy, capitalizing on vulnerabilities related to ongoing events like the COVID-19 pandemic.
- •Gains initial access through social engineering, phishing, and exploiting known software vulnerabilities.
- •Adopts zero-day vulnerabilities for breaches, indicating a shift towards more advanced hacking techniques.
- •Ransom demands are typically high, reflecting their focus on financial gain through data exfiltration.
Threat Level & Status Breakdown
For spacebears · Based on incidents in selected period
Status Breakdown
Recent activity
Monthly attack count for spacebears in the selected period
Intelligence
IOCs, YARA/Sigma rules, and related families for spacebears
- 5butbkrljkaorg5maepuca25oma7eiwo6a2rlhvkblb4v6mf3ki2ovid.onion
TTPs & Attack Vectors
Tools, initial access, and MITRE ATT&CK techniques for spacebears
T1486
T1486
T1490
T1490
T1078
T1078
T1041
T1041
T1562
T1562
T1021
T1021
T1059
T1059
T1021.001
T1021.001
T1105
T1105
T1033
T1033
T1110
T1110
T1583
T1583
Affected countries(36)
Countries where this group has been reported to target or leak victims.