SPACEHOP Activity is an intrusion activity cluster associated with the use of operational relay box (ORB) infrastructure to support covert command-and-control and access operations. It has been linked to APT5-related tradecraft and is characterized by the use of acquired virtual private servers as control systems for compromised relay nodes, along with multi-hop proxy chains built from compromised network devices to conceal operator origin and proxy command-and-control traffic. The activity has also been associated with the use of a command-and-control framework sourced from a public GitHub repository to administer relay nodes and with enabling exploitation of CVE-2022-27518 for illegitimate access. SPACEHOP Activity appears to function primarily as enabling infrastructure and access support rather than as a distinct ransomware operation. Its observed tradecraft centers on anonymized relay architecture, traffic proxying, and command-and-control resilience. Known reporting ties this activity to broader APT5 operations that have included exploitation of public-facing appliances, persistence through web shells and modified legitimate components, credential theft, lateral movement, data staging and exfiltration, and defense evasion, but the high-confidence characteristics specific to SPACEHOP Activity are the operation of VPS-backed ORB infrastructure and the routing of traffic through chains of compromised network devices.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Activity cluster leveraging ORB infrastructure, VPS-based control systems, public GitHub-sourced tooling, multi-hop proxying through compromised network devices, and exploitation of Citrix infrastructure for illegitimate access.
Uses chains of compromised network devices as proxy infrastructure for C2 communications.
Uses compromised network devices as relay infrastructure to proxy C2 communications.
Uses acquired VPSs as control systems for devices in an ORB network.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.