Adversary Intelligence — 2026-05-04

Cyber Spies Target Russian Aviation Firms to Steal Satellite and GPS Data

Kaspersky published a report on April 29 identifying HeartlessSoul as an espionage group, active since at least September 2025, targeting Russian government agencies and aviation companies to steal GIS files containing detailed infrastructure mapping. The group gains access through phishing emails with infected archives, malicious ads mimicking aviation software sites, and a trojanized GearUP installer uploaded to SourceForge, according to Kaspersky. Deployed malware captures screenshots, keystrokes, browser data, Telegram credentials, and device location. Kaspersky identified technical overlaps with Goffee, a previously documented group known for flash-drive exfiltration; Russian analyst Oleg Shakirov noted on Telegram that some malware samples were distributed disguised as FPV drone simulator files and Starlink bypass tools.

Analysis
The GIS and satellite positioning files HeartlessSoul is extracting from Russian aviation firms point to precision strike or counter-navigation tasking in the Ukraine theater. The FPV simulator and Starlink bypass lures are too operationally specific to be incidental, narrowing tasking authority to a party with direct conflict stakes. Per Kaspersky's reporting (The Record as sole independent account), the group shares infrastructure or developer DNA with Goffee, though that overlap doesn't settle attribution. The operation may instead serve a criminal market selling conflict-era geospatial data rather than passing it to a state taskmaster. Attribution of a Russian state-linked cyber operation against Western aviation is likely before August 2026, as both sides now contest aviation-sector geospatial data.
1 sources
  1. Cyber spies target Russian aviation firms to steal satellite and GPS data - The Record

View in full brief →

UNCLASSIFIED // OPEN SOURCE