Space Bears is a ransomware and extortion threat actor that emerged in April 2024 and is commonly associated with the Phobos ransomware-as-a-service ecosystem. The group is also tracked under the aliases spacebears and space_bears. Reporting consistently characterizes Space Bears as a double-extortion operation that steals data and threatens publication on a dedicated leak site, while in some cases also deploying file encryption. Its leak infrastructure is used to pressure victims with countdown timers, public shaming, and offers to sell stolen data to third parties if ransom demands are not met. Space Bears has targeted organizations across multiple regions and sectors, including telecommunications, managed services, business services, manufacturing, technology, and other enterprise environments. Observed victimology includes companies in Europe, Latin America, Asia-Pacific, and the Middle East, as well as incidents involving service providers and contractors whose compromise could expose downstream customer or partner data. The group has also claimed access to data belonging to larger brands through breaches at third-party suppliers or engineering contractors, indicating opportunistic supply-chain and indirect targeting. The actor’s operations are primarily consistent with financially motivated ransomware activity rather than espionage. Publicly reported incidents indicate a strong emphasis on data theft, leak-site publication, and coercive negotiation tactics. In several cases, Space Bears has claimed theft of databases, financial records, customer and employee information, technical documentation, and production or configuration data. The group has been described as willing to publish stolen material when victims do not pay and, in some cases, to market allegedly stolen data for sale. Available reporting links Space Bears to the broader Phobos ecosystem, suggesting either operational dependence on or close affiliation with that criminal service model. High-confidence public information does not establish it as a nation-state actor. Overall, Space Bears is best understood as a relatively new but active ransomware/extortion operation focused on monetizing intrusions through exfiltration-led extortion, leak-site pressure, and occasional encryption deployment.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware attack against BiesSse Group involving a data breach and alleged theft of employee and client personal information, financial documents, and an SQL database.
Ransomware group attributed with an attack against Anpra SAS involving a data breach and theft of personal information, financial documents, and other files.
Conducting a ransomware attack and data breach against DoAllTech, with claimed theft of employee and client personal information, financial documents, and other files.
Ransomware group reported targeting a pharmaceutical/biotech organization.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.