SPACESHIP is a Windows malware family associated with collection and exfiltration activity, particularly in environments where removable media is used. It has been documented establishing persistence through boot or logon autostart mechanisms, including use of the Startup folder and shortcut modification. SPACESHIP performs file and directory discovery, identifies files of interest by extension, and copies selected data into a staging location within the user profile. It can archive collected data using a custom method before exfiltration. A notable characteristic is exfiltration over USB or other physical removable media rather than relying solely on network channels. The malware is part of a cluster of related implants that emphasize persistence, local staging, and removable-media-based collection workflows on Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 distinct techniques documented for this family, organized by ATT&CK tactic.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
C:\Users\[Username]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
ADVSTORESHELL achieves persistence by adding itself to the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key... APT28 has deployed malware that has copied itself to the startup directory for persistence... FIN7 malware has created Registry Run and RunOnce keys to establish persistence, and has also added items to the Startup folder.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware that persists by creating a shortcut in the current user's Startup folder.
Backdoor malware that persists by creating a shortcut in the user's Startup folder.
Data theft malware that archives and stages collected data locally, persists via registry run keys and shortcut modification, performs file and directory discovery, and exfiltrates data over USB.
Backdoor that collects targeted file types and stages them in a user profile directory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.