← Back to all campaigns
ActiveMITRE ATT&CK

SPACEHOP Activity

SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged for SPACEHOP Activity enabled China-nexus cyber threat actors – such as APT5 and Ke3chang – to perform network reconnaissance scanning and vulnerability exploitation. SPACEHOP Activity has historically targeted entities in North America, Europe, and the Middle East.

First observedJan 1, 2019
Last observedMay 1, 2024
Attributed actors2
Source-backed events4
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

APT5

APT5 is a China-based espionage actor that has been active since at least 2007 primarily targeting the telecommunications, aerospace, and defense industries throughout the U.S., Europe, and Asia. APT5 has displayed ad...

mitre-attckReview source
Source ReportedActive actor

Ke3chang

Ke3chang is a threat group attributed to actors operating out of China. Ke3chang has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean, Europe, and North America sinc...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

APT5 attributed to this campaign

Attribution confidence: Source Reported.

Cataloged
Attribution

Ke3chang attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

SPACEHOP Activity last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

SPACEHOP Activity first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Related vulnerabilities 0

No linked CVEs are available.

Malware and tools 24

  • MirageFoxMalware | Ke3chang
  • NeoichorMalware | Ke3chang
  • OkrumMalware | Ke3chang
  • PACEMAKERMalware | APT5
  • PULSECHECKMalware | APT5
  • PoisonIvyMalware | APT5
  • RAPIDPULSEMalware | APT5
  • SLIGHTPULSEMalware | APT5
  • SLOWPULSEMalware | APT5
  • Skeleton KeyMalware | APT5
  • gh0st RATMalware | APT5
  • MimikatzTool | APT5

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.