The Space Pirates hacking group has been linked to attacks against at least 16 organizations in Russia and Serbia in the past year, using new tactics and adding new cyber tools to its arsenal.
See also: Hackers rent WikiLoader to attack Italian organizations with banking trojan

“The cybercriminals’ primary goals are still espionage and theft of confidential information, but the group has expanded its interests and the geography of its attacks,” Positive Technologies said in a deep-dive report published last week.
Targets include government agencies, educational institutions, private security companies, aerospace manufacturers, agricultural producers, defense, energy, and healthcare companies in Russia and Serbia.
See also: Minecraft: BleedingPipe vulnerability puts players at risk
Space Pirates was first discovered by a Russian cybersecurity firm in May 2022, highlighting its attacks on the country's aerospace sector. Space Pirates, which appears to have been active since at least late 2019, has connections to another adversary tracked by Symantec as Webworm.
Analysis of the attack infrastructure by Positive Technologies revealed the perpetrator's interest in collecting PST email files as well as the use of Deed RAT, a malicious software product attributed exclusively to the adversarial collective.
Deed RAT is said to be the successor to ShadowPad, itself an evolution of PlugX, both of which are widely used by Chinese cyberattack groups. In active development, the malware comes in 32- and 64-bit versions and is equipped to dynamically retrieve additional add-ons from a remote server.
This includes a Disk plug-in to list files and folders, execute commands, write arbitrary files to disk , and connect to network drives, as well as a Portmap module used for port forwarding.
See also: P2PInfect malware: Attacks on SSH and Redis to create botnets

The Deed RAT also acts as a conduit for delivering subsequent next-stage payloads, such as Voidoor, a previously undocumented malware designed to communicate with a legitimate forum named Voidtools and a GitHub repository associated with a user named “hasdhuahd” for command-and-control (C2).
Voidtools is the developer of a free desktop search utility for Microsoft Windows called Everything, with its forum powered using open source software called MyBB. Voidoor's primary goal is to log in to the forum using hard-coded credentials and gain access to the user 's personal messaging system to search for a folder matching a specific victim ID.
Evidence shows that the GitHub and voidtools accounts were registered sometime in November 2022.
Information source: thehackernews.com
