Space Bears, also known as spacebears and space_bears, is a financially motivated ransomware and data-extortion operation that emerged in April 2024. The group operates a dedicated leak site and has claimed victims across multiple regions and sectors, including healthcare, information technology, telecommunications, retail, professional services, food production, logistics-related services, and automotive-parts distribution. Reported targets include organizations in Italy, Brazil, Australia, Switzerland, Colombia, the Czech Republic, Germany, South Korea, Mexico, and the United States. Space Bears has claimed theft of databases, personal information, financial records, technical documents, and other business data. Its extortion model includes threatening publication of allegedly stolen material and, in some cases, offering data for sale if a victim does not pay. Public reporting identifies the operation as ransomware-related, but does not establish a consistent initial-access method, malware family, encryption behavior, or geographic origin.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted a ransomware attack against Schwartz, Giannini, Lantsberger & Adamson (SGLA), a US accounting firm.
Conducting a ransomware attack against an Italian ophthalmology clinic.
Conducting a ransomware attack resulting in a data breach against Freelom, a Czech internet service provider and IT company.
Conducting a ransomware attack resulting in a data breach against Holzmarkt Chemnitz, with stolen data reportedly including personal information, financial documents, and an SQL database.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.