Ransomware
Space BearsSpaceBears
Attribution
No confirmed nation-state or named-crew attribution. Public reporting (S-RM, April 2024) links the Space Bears leak site to a 'Faust' operator, an affiliate of the Phobos ransomware-as-a-service operation, meaning Space Bears is best understood as a data-leak/extortion brand operated by a Phobos/Faust affiliate rather than a distinct malware family. Underlying operators are unknown; some open-source commentary speculates a possible Russian-speaking/CIS nexus, but this is unconfirmed and should be treated as low confidence.
Motivation
Financial (double-extortion ransomware / data-leak extortion)
Attribution confidence
medium
MENA targeting
Egypt, Saudi Arabia
Sectors
Hospitality, technology
Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Why it mattersRansomware actor, medium confidence, documented targeting Egypt, Saudi Arabia (Hospitality, technology sectors).
What's nextNo pipeline reports reference this actor yet — Radar mentions may still surface early signal.
No open hunts or recent alerts tracked against this actor right now.