Erudite Mogwai
Erudite Mogwai is an Asian/China-nexus threat actor also referred to in the provided content as Space Pirates and Webworm. The group has been observed targeting Russian organizations, including Russian government-sector entities and Russian IT organizations/companies. Reported activity includes attacks against the IT infrastructure of a Russian government organization, Russian IT companies, and a spring 2025 compromise of a government-sector organization whose infrastructure was assessed as likely compromised by Erudite Mogwai. The actor has been linked in the content to deployment of LuckyStrike Agent, a multifunctional .NET backdoor, and to NetDraft, which Solar refers to as LuckyStrike Agent in this context. LuckyStrike Agent was observed using AppDomain Manager Injection to load into the legitimate Microsoft UE-V component UevAppMonitor.exe and using Microsoft OneDrive via Microsoft Graph API as command-and-control. The malware supports shell execution, file upload/download, directory browsing, plugin execution, arbitrary .NET assembly execution, host metadata collection, RSA-encrypted data transmission, and task retrieval from OneDrive folders. The content also notes LuckyStrike Agent appears professionally developed and may be a commercial or closed-market malware product. In the spring 2025 investigation, Erudite Mogwai was associated with a broader intrusion set on a compromised Microsoft Exchange server that had been exposed via the ProxyShell chain (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207). Investigators found multiple malware families co-resident on the server, including ShadowPad, Shadowpad Light/Deed RAT, Donnect, Mythic Agent, and a previously undocumented modular backdoor named ShadowRelay. ShadowRelay was described as a plugin-based implant capable of client/server operation, optional process injection, anti-analysis checks, Windows service installation, self-removal, AES-encrypted communications, and port-reuse/packet-diversion using WinDivert to relay communications and hide C2 traffic. The content also states Erudite Mogwai has operational similarities with other China-aligned activity clusters but does not confirm identity overlap. ESET noted similarities between LongNosedGoblin and Erudite Mogwai, while also stating it could not confirm they are the same group due to differences in TTPs. A Rostelecom security team report cited Erudite Mogwai (Space Pirates) as one of at least three APT groups present on a Russian organization’s network, alongside Obstinate Mogwai and GOFFEE.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Software & Services
- Government & Administration
Where they target
Geographies tied to known operations.
- 🇷🇺 Russia
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Associated vulnerabilities
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...источником их заражения оказался почтовый сервер Exchange, который оказался скомпрометированным еще летом 2024 года с помощью эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
...эксплуатации цепочки уязвимостей ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207).
Observables
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor associated with deploying the same NosyDoor/LuckyStrike Agent malware against Russian IT organizations.
Threat cluster reported using NetDraft against Russian IT organizations in 2024.
Named APT cluster reported present on a Russian organization’s network (per Rostelecom security team reporting).
Вероятная компрометация организации госсектора через уязвимый Microsoft Exchange; на зараженных системах обнаружен Shadowpad Light (Deed RAT).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.