Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Space Bears is a double-extortion ransomware/data-leak operation that emerged in April 2024. It is notable for a deliberately professional, 'corporate'-styled data leak site using stock photography, polished design, and written 'guarantees' to victims that stolen data will be deleted and decryption provided upon payment. Reporting ties the operation to the Phobos RaaS ecosystem via a Faust affiliate. It practices data exfiltration prior to encryption and threatens publication on its Tor leak site to pressure payment, primarily targeting small-to-medium organizations.
Additional names this actor is known by across other vendors' naming schemes — cross-referenced from external crosswalk sources, not RaqibCTI's own curated aliases (shown at the top of this page). Each source is attributed to its own licence.
Space Bears' leak site first surfaced in April 2024, when S-RM's threat intelligence team identified a Faust operator (an affiliate within the Phobos ransomware-as-a-service program) using the new site to extort a victim. Rather than being a novel encryptor, Space Bears functions as an extortion/leak brand layered on Phobos-family tooling, consistent with the broader Phobos pivot from encryption-only toward double extortion (data theft via tools such as MegaSync, per-system ransom demands typically in the ~$10k-$20k range). The group is distinguished less by technical novelty than by presentation: a corporate-aesthetic leak portal with stock imagery and formal 'guarantee' language designed to project legitimacy and pressure payment. Victimology is broad and opportunistic across ~45 countries, skewing to the United States and Western Europe (Italy, Germany, Spain) and concentrated in Professional Services, Technology, Manufacturing, Healthcare, and Retail/E-Commerce. Notable claims include a Comcast-related breach via contractor Quasar Inc. and a claim against Mexican retailer Sears/Grupo Sanborns. As of early September 2026 ransomware.live tracks roughly 150+ claimed victims and lists the group as still active, though with a reported recent decline in posting velocity. Reporting overall remains limited and largely vendor/aggregator-derived, so specific TTP detail beyond the Phobos/Faust lineage and exfil-then-encrypt pattern is thin. MENA relevance: LOW but REAL, not fabricated. Ransomware.live lists exactly one Egypt victim (Sharm Reef Hotel) and one Saudi Arabia victim (Texcomp), plus one UAE victim (Sawa International). These appear to be genuine leak-site postings but are single, opportunistic entries out of ~150 global victims with no evidence of MENA-focused targeting or campaign intent. Verdict: the RaqibCTI Egypt and Saudi Arabia tags are REAL leak-site victims but thin and opportunistic; keep them, but do not characterize Space Bears as a MENA-oriented actor.
+10 more relationships — see the relationships browser.