Skip to main content
Mallory
4 malware familiesExploits CVEs in the wild

Erudite Mogwai

Also known aserudite_mogwai

Erudite Mogwai is an Asian/China-nexus threat actor also referred to in the provided content as Space Pirates and Webworm. The group has been observed targeting Russian organizations, including Russian government-sector entities and Russian IT organizations/companies. Reported activity includes attacks against the IT infrastructure of a Russian government organization, Russian IT companies, and a spring 2025 compromise of a government-sector organization whose infrastructure was assessed as likely compromised by Erudite Mogwai. The actor has been linked in the content to deployment of LuckyStrike Agent, a multifunctional .NET backdoor, and to NetDraft, which Solar refers to as LuckyStrike Agent in this context. LuckyStrike Agent was observed using AppDomain Manager Injection to load into the legitimate Microsoft UE-V component UevAppMonitor.exe and using Microsoft OneDrive via Microsoft Graph API as command-and-control. The malware supports shell execution, file upload/download, directory browsing, plugin execution, arbitrary .NET assembly execution, host metadata collection, RSA-encrypted data transmission, and task retrieval from OneDrive folders. The content also notes LuckyStrike Agent appears professionally developed and may be a commercial or closed-market malware product. In the spring 2025 investigation, Erudite Mogwai was associated with a broader intrusion set on a compromised Microsoft Exchange server that had been exposed via the ProxyShell chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207). Investigators found multiple malware families co-resident on the server, including ShadowPad, Shadowpad Light/Deed RAT, Donnect, Mythic Agent, and a previously undocumented modular backdoor named ShadowRelay. ShadowRelay was described as a plugin-based implant capable of client/server operation, optional process injection, anti-analysis checks, Windows service installation, self-removal, AES-encrypted communications, and port-reuse/packet-diversion using WinDivert to relay communications and hide C2 traffic. The content also states Erudite Mogwai has operational similarities with other China-aligned activity clusters but does not confirm identity overlap. ESET noted similarities between LongNosedGoblin and Erudite Mogwai, while also stating it could not confirm they are the same group due to differences in TTPs. A Rostelecom security team report cited Erudite Mogwai (Space Pirates) as one of at least three APT groups present on a Russian organization’s network, alongside Obstinate Mogwai and GOFFEE.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Software & Services
  • Government & Administration

Where they target

Geographies tied to known operations.

  • 🇷🇺 Russia
MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

4 of 15 tactics7 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1583
Acquire Infrastructure
T1583.001
Domains
TA0002
Execution
1 technique
T1574
Hijack Execution Flow
T1574.014
AppDomainManager
TA0005
Stealth
1 technique
T1574
Hijack Execution Flow
T1574.014
AppDomainManager
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
IOCS

Observables

33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs3

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables33

Domains, IPs, and hashes tied to this actor, refreshed continuously.

Erudite Mogwai | Mallory