No confirmed nation-state or named-crew attribution. Public reporting (S-RM, April 2024) links the Space Bears leak site to a 'Faust' operator, an affiliate of the Phobos ransomware-as-a-service operation, meaning Space Bears is best understood as a data-leak/extortion brand operated by a Phobos/Faust affiliate rather than a distinct malware family. Underlying operators are unknown; some open-source commentary speculates a possible Russian-speaking/CIS nexus, but this is unconfirmed and should be treated as low confidence.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Phobos/Faust lineage disables the Windows firewall via 'netsh firewall set opmode mode=disable' (CISA AA24-060a); SOS Ransomware notes the family 'disables firewalls' in Space Bears intrusions.
S-RM advisory: the Phobos/Faust operator using the Space Bears leak site exfiltrates victim data with MegaSync to Mega cloud storage before posting it.
S-RM and Alphahunt document the double-extortion pivot: stolen data published on the Space Bears Tor 'wall of shame' leak site (first 8 victims Apr 2024) to coerce ransom payment.
All sources (S-RM, Alphahunt, Solace, ransomware.live) describe Space Bears encrypting victim data with the Phobos/Faust encryptor as the core of its double-extortion model.
ransomware.live lists bcdedit, vssadmin and WMIC shadow-copy/backup destruction for Space Bears; CISA AA24-060a documents 'vssadmin delete shadows /all /quiet' and WinRE disabling for Phobos.
S-RM (Apr 2024) and SOS Ransomware describe the Faust/Phobos operator behind Space Bears entering via unprotected or poorly protected RDP; CISA AA24-060a lists exposed RDP as the primary Phobos vector.
Solace Cyber and Alphahunt cite phishing emails as a Space Bears entry vector; CISA AA24-060a documents Phobos spearphishing with malicious attachments (SmokeLoader dropper).
Alphahunt maps T1078 for Space Bears; Phobos affiliates authenticate over RDP with compromised or brute-forced credentials (CISA AA24-060a).
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Spacebears's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
protect · 9 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialApp GovernanceT1562significantAnti-SpoofingT1566significantDefender for Cloud AppsT1133partialDefender for Cloud AppsT1567partialDefender for Cloud AppsT1567.002partialConditional AccessT1078minimalIdentity Secure ScoreT1078minimalMultifactor AuthenticationT1078minimalMultifactor AuthenticationT1566partialMultifactor AuthenticationT1566.001partialPrivileged Identity ManagementT1078minimalPassword PolicyT1078significantPassword ProtectionT1078partialRole Based Access ControlT1059minimalRole Based Access ControlT1078minimalRole Based Access ControlT1562minimalAntimalwareT1027significantAntimalwareT1059significantAntimalwareT1566significantAntimalwareT1566.001significantAnti-PhishingT1566significantAnti-PhishingT1566.001significantAntiSpamT1566significantAntiSpamT1566.001significantAudit SolutionsT1078partialAudit SolutionsT1562partialInformation ProtectionT1567significant
detect · 10 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantApp GovernanceT1078significantApp GovernanceT1562significantApp GovernanceT1566significantAdvanced Threat HuntingT1078significantAdvanced Threat HuntingT1562significantAdvanced Threat HuntingT1566significantAdvanced Threat HuntingT1567significantDefender for Cloud AppsT1078partialDefender for Cloud AppsT1133partialDefender for Cloud AppsT1486partialDefender for Cloud AppsT1567partialDefender for Cloud Apps
respond · 7 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAutomated Investigation and ResponseT1078significantAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantAutomated Investigation and ResponseT1567significantIncident ResponseT1059minimalIncident ResponseT1078minimalIncident ResponseT1562minimalIncident ResponseT1566minimalQuarantine PoliciesT1027significantQuarantine PoliciesT1566significantQuarantine PoliciesT1566.001significant
Countermeasures · D3FEND
Defensive techniques that counter Spacebears's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.