A cyber espionage group dubbed HeartlessSoul is targeting aerospace firms and drone operators to steal geospatial mapping data, including GIS files, terrain models, and GPS data. The group uses phishing, malvertising, fake software installers, and a fraudulent SourceForge project to compromise systems. Techniques include a JavaScript RAT, PowerShell scripts, and a Windows shortcut zero-day exploit (ZDI-CAN-25373). Victims are primarily Russian government and enterprise entities. Attribution remains uncertain, with Russian firms linking the group to 'Versatile Werewolf' and possibly pro-Ukrainian actors. Security experts recommend zero-trust access controls and network segmentation for systems handling crown-jewel GIS data.

5m read timeFrom darkreading.com
Post cover image
Table of contents
Geospatial Files, Hidden CommandsAttribution Uncertain
114 Impressions