logo

Cyber Espionage Group Targets Aviation Firms to Steal Map Data

ID: 70307162-ec84-5248-88ae-7bb663763e80

STIX ID: report--70307162-ec84-5248-88ae-7bb663763e80

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Robert Lemos

...
...

Kaspersky researchers observed a sophisticated espionage campaign dubbed HeartlessSoul that uses phishing, malvertising, fake download pages (including a planted SourceForge project), JavaScript RATs, PowerShell scripts, fileless execution and LNK exploit chains to steal GIS/GPS and other geospatial data from government and enterprise targets; the activity (tracked since at least Feb 2025 with origins back to Sep 2025) aims to collect operational mapping and navigation intelligence, attribution is unresolved, and defenders are advised to harden GIS workflows with zero-trust, segmentation, and focused monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.