SPACEHOP is an operational relay box (ORB) network that uses compromised network devices, particularly small-office/home-office (SOHO) routers, as intermediary infrastructure. It routes command-and-control communications through chains of compromised devices, providing multi-hop proxying that obscures the origin of malicious traffic. SPACEHOP denotes the relay network rather than a definitively attributed threat group.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as an operational relay network for background comparison. Its documented targeting centers on SOHO routers; no infrastructure or indicator overlap with the analyzed AVERAT campaign was found.
Proxied command-and-control through chains of compromised network devices.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.