Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Webworm

Also known as: Space Pirates

Description

Space Pirates is a cybercrime group that has been active since at least 2017. They primarily target Russian companies and have been observed using various malware, including Deed RAT and ShadowPad. The group uses a combination of publicly available tools and their own protocols to communicate with their command-and-control servers.

Goals & Targeting

Targeted Sectors

Government
Education

Targeted Countries / Regions

Belgium
Czechia
Hungary
Italy
Nigeria
Poland
Serbia
South Africa
Spain

AI Analysis

· 1 week ago

Executive Summary

Webworm, also known as Space Pirates, is a cybercrime threat actor targeting government and education sectors in multiple countries. Since their activity began in 2017, they have been linked to the use of malware such as Deed RAT and ShadowPad, employing both public tools and custom protocols for communication with command-and-control servers.

Goals & Targeting

Webworm's targeting of government and education sectors suggests potential interests in sensitive data or financial gain. Their focus on multiple countries may indicate a broad operational reach or strategic objectives related to espionage or theft.

Enhanced Description

Webworm (aka Space Pirates) is a cybercrime group active since at least 2017, primarily targeting Russian companies but also government and education sectors across several countries. They utilize malware like Deed RAT and ShadowPad, combining public tools with custom protocols to communicate with servers. Despite their activity span, details on their primary motivations, goals, and exact tactics remain unclear, creating uncertainty in threat intelligence.

Key Capabilities

  • Malware development/deployment (Deed RAT, ShadowPad)
  • Use of public tools combined with custom protocols for C2

Software / Tooling

Deed RAT
ShadowPad

Campaigns & Victims

Webworm's campaigns show persistence and operational skill in leveraging malware. Notable for their malware toolset but lacks specific known campaigns beyond targeting Russian companies.

IOC Patterns

  • Presence of Deed RAT/ShadowPad malware indicators
  • Network traffic indicative of C2 protocols used by Webworm

Recommended Actions

  • Monitor for custom protocol-based C2 activity
  • Implement endpoint detection to identify Deed RAT/ShadowPad signatures
  • Conduct regular vulnerability assessments in targeted sectors

Suggested Tags

APT
cybercrime
espionage
government
education

Confidence Assessment

Medium confidence due to known malware usage and targets, yet gaps exist in their motivations, TTPs depth, and campaign specifics.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
cybercrime
espionage
government
education

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.