ATT&CKCampaignsSPACEHOP Activity

SPACEHOP Activity

C0052

Campaign, Jan 2019 to May 2024.View on attack.mitre.org

About this campaign

SPACEHOP Activity is conducted through commercially leased Virtual Private Servers (VPS), otherwise known as provisioned Operational Relay Box (ORB) networks. The network leveraged for SPACEHOP Activity enabled China-nexus cyber threat actors – such as APT5 and Ke3chang – to perform network reconnaissance scanning and vulnerability exploitation. SPACEHOP Activity has historically targeted entities in North America, Europe, and the Middle East.

Techniques used4

Procedure examples4

TechniqueProcedure example
T1090.003
Multi-hop Proxy

SPACEHOP Activity has routed traffic through chains of compromised network devices to proxy C2 communications.

T1190
Exploit Public-Facing Application

SPACEHOP Activity has enabled the exploitation of CVE-2022-27518 and CVE-2022-27518 for illegitimate access.

T1583.003
Virtual Private Server

SPACEHOP Activity has used acquired Virtual Private Servers as control systems for devices within the ORB network.

T1588.002
Tool

SPACEHOP Activity leverages a C2 framework sourced from a publicly-available Github repository for administration of relay nodes.

Attributed groups2

Software0

None recorded.

References1

  1. ORB Mandiant Open source
    Raggi, Michael. (2024, May 22). IOC Extinction? China-Nexus Cyber Espionage Actors Use ORB Networks to Raise Cost on Defenders. Retrieved July 8, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.