Space Bears is a ransomware operation whose leak site was first identified in April 2024. The provided reporting associates Space Bears with the Phobos ransomware-as-a-service (RaaS) ecosystem. High-confidence victim reporting in the content states that Space Bears published data allegedly stolen from Kymco (Kwang Yang Motor Co., Ltd.) in Taiwan, including patent and innovation data, financial data, and customer and partner data. Separate reporting states that Space Bears attacked Texcomp in Saudi Arabia and exposed an SQL database containing client and partner contact information. Based on the cited incidents, Space Bears conducts data theft and public leak activity consistent with double-extortion ransomware operations. The content does not provide additional confirmed technical details such as encryption routine, initial access vector, ransom note filename, or specific malware indicators for Space Bears.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware operation with a dedicated leak site (identified April 2024) emphasizing data theft for extortion and using double-extortion tactics (exfiltration plus encryption). Reported as associated with the Phobos RaaS ecosystem.
Ransomware actor operating a leak site (first identified April 2024 per content) and using double extortion (exfiltration plus encryption); described as associated with the Phobos RaaS ecosystem.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.