Adversary Intelligence — 2026-05-11

Cyber Espionage Group Targets Aviation Firms to Steal Map and Navigation Data

Kaspersky Lab reported on April 29 that HeartlessSoul has targeted Russian government agencies and aerospace companies through phishing and malvertising since at least September 2025, a finding corroborated by Positive Technologies and BI.ZONE, which tracks the group as Versatile Werewolf. The campaigns deliver a JavaScript RAT through fake aviation software installers, including a fraudulent SourceForge project, exploiting the ZDI-CAN-25373 Windows shortcut vulnerability to conceal malicious commands. The trojan collects GPS tracks, GIS shape files, digital terrain models, and proprietary mapping formats alongside browser credentials and Telegram session data. Kaspersky identified infrastructure overlap with the GOFFEE APT group; none of the three firms has publicly attributed the campaign to a state sponsor.

Analysis
The targeting of GPS tracks, digital terrain models, and proprietary GIS shapefiles points to collection requirements beyond criminal profit, suggesting an actor with sustained operational interest in Russian aerospace and military-adjacent government targets. Infrastructure overlap with GOFFEE, previously linked to pro-Ukrainian operations against Russian defense contractors, is the strongest available attribution signal, corroborated across three Russian-origin vendors (Kaspersky, Positive Technologies, BI.ZONE), though the absence of independent Western tracking limits verification. Formal state attribution is unlikely within six months of public disclosure: Russian firms face structural constraints on naming Ukraine-aligned actors, and infrastructure co-location alone falls short of most public attribution thresholds. Shared or compromised hosting staging a false-flag against GOFFEE would equally explain the observed overlap.
1 sources
  1. Cyber Espionage Group Targets Aviation Firms to Steal Map Data - Dark Reading

View in full brief →

UNCLASSIFIED // OPEN SOURCE