# Sophisticated Cyber Espionage Campaign Targets Aviation Industry for Geospatial Intelligence
Kaspersky Lab has uncovered a coordinated espionage campaign targeting aerospace firms and unmanned aircraft operators, revealing how nation-state threat actors are systematically harvesting geospatial data and GPS intelligence to support regional military conflicts.
## The Threat
A cyber espionage group tracked as HeartlessSoul has launched a multi-faceted attack campaign designed to compromise aviation and drone operations companies and exfiltrate sensitive geospatial information systems. The threat actor operates through meticulously crafted phishing and malvertising campaigns that trick employees into downloading what appears to be legitimate aviation software—but is actually malware designed to establish persistent access and steal mapping data, terrain models, and Global Positioning System (GPS) information.
According to Kaspersky Lab's analysis, the group demonstrates "sophisticated" capabilities characteristic of state-sponsored operations rather than cybercriminal enterprises. The campaign exhibits hallmarks of advanced persistent threats (APTs), including:
The primary targets have been aerospace contractors and drone operators, with victims currently concentrated among Russian government entities and commercial enterprises—suggesting the campaign may be connected to ongoing regional military conflicts where accurate mapping and intelligence data prove strategically valuable.
## Background and Context: The Geospatial Intelligence Arms Race
The rise of HeartlessSoul reflects a broader shift in cyber espionage priorities. As military conflicts evolve and precision operations depend increasingly on accurate geospatial information, threat actors are pivoting away from traditional targets like financial data or intellectual property toward mapping intelligence, GPS coordinates, and terrain models that directly support offensive and defensive military operations.
"With several ongoing regional military conflicts and an increase in interference with global navigation satellite systems (GNSS), geospatial data has become a more common, if not popular, target for some threat groups," Kaspersky Lab noted.
This trend is not new but is intensifying. In 2024, IntelBroker—a pseudonymous hacker later identified as British national Kai West—claimed responsibility for breaching Space-Eyes, a Miami-based geospatial intelligence company. Though analysts subsequently cast doubt on some of IntelBroker's claims, the breach highlighted the value threat actors place on geospatial data. West was arrested in June 2025, but his activity underscored that both state and non-state actors recognize mapping intelligence as a high-value target.
The convergence of three factors makes geospatial data particularly attractive:
1. Military dependence: Modern conflicts rely on accurate mapping for targeting, logistics, and operational planning
2. Dual-use nature: GPS and GIS data serve both civilian and military purposes, making theft difficult to trace
3. Persistent value: Unlike stolen financial records, geospatial intelligence remains operationally useful for years
## Technical Details: Attack Methodology and Infrastructure
HeartlessSoul's operational approach combines social engineering, infrastructure deception, and advanced malware techniques to compromise target organizations.
### Attack Vector #1: Phishing Campaigns
The group crafts convincing phishing emails that deliver links to attacker-controlled domains impersonating legitimate aviation software vendors and flight planning tools. These emails target employees at aerospace firms and drone manufacturers, leveraging industry-specific terminology and branding to increase credibility.
### Attack Vector #2: Malvertising
Alongside phishing, HeartlessSoul deploys malvertising campaigns—malicious advertisements placed on legitimate websites—that direct visitors to compromised download pages hosting infected software packages.
### Attack Vector #3: Compromised Supply Chain
In a particularly brazen maneuver, the threat actor created a fake project on SourceForge, a widely-trusted open-source software repository. Users seeking legitimate tools unknowingly downloaded malicious archives, demonstrating the group's willingness to compromise trusted distribution channels.
### Infection Chain
Once executed, the malware initiates a multi-stage infection sequence:
| Stage | Purpose | Technique |
|-------|---------|-----------|
| Stage 1 | Initial access & reconnaissance | Phishing/malvertising delivers loader |
| Stage 2 | Privilege escalation & persistence | Multi-stage implant installation |
| Stage 3 | Defense evasion | Fileless execution, in-memory operations |
| Stage 4 | Data discovery & exfiltration | GIS files, GPS data, terrain models |
The use of fileless execution—running malware directly in memory rather than writing executable files to disk—significantly complicates detection by traditional antivirus tools and endpoint protection systems.
### Data Targets
The campaign specifically focuses on:
## Implications: Who Is Threatened?
The immediate risk extends beyond the currently targeted Russian aviation sector.
Aerospace and defense contractors worldwide operating in contested regions face elevated risk, particularly those involved in:
Commercial aviation companies and regional airlines serving conflict zones may be inadvertent secondary targets if their infrastructure or routing data becomes militarily relevant.
Civilian geospatial firms providing mapping services, GPS infrastructure, or terrain modeling to governments or militaries should assume they are on threat actor targeting lists.
The sophistication and resources evident in HeartlessSoul's operations suggest nation-state sponsorship, likely to support ongoing military activities. This implies the campaign will continue adapting and expanding as long as regional conflicts create demand for geospatial intelligence.
## Recommendations for Defenders
Organizations in aerospace, defense, and geospatial sectors should implement immediate mitigations:
---
## HackWire Analysis
The emergence of HeartlessSoul represents a fundamental shift in espionage priorities that defenders must recognize and adapt to. For years, cyber threat intelligence has focused on financial data, intellectual property, and credentials. But as military conflicts increasingly depend on precision operations, geospatial intelligence has become as strategically valuable as nuclear secrets—and it's far easier to steal.
What makes this campaign particularly dangerous is that it exploits a blind spot in conventional cybersecurity. Most organizations and government agencies have mature defenses around financial systems, classified networks, and human intelligence operations. But GIS files, terrain models, and GPS databases often live in less-protected systems because they're classified as "operational support" rather than "top-secret intelligence."
HeartlessSoul's willingness to compromise SourceForge—a platform trusted by millions of developers—signals that threat actors no longer fear reputational consequences when they attack trusted supply chains. They understand that the window between discovery and exploitation is measured in months, and the intelligence value of one successful breach justifies the eventual exposure.
For aerospace and defense contractors: assume your geospatial and GPS data is already in the crosshairs. The question is not whether sophisticated adversaries want it, but whether your detection capabilities can catch exfiltration before it happens. Behavioral monitoring, data-loss prevention, and network segmentation around geospatial systems are no longer optional—they're foundational security requirements.
The pattern also extends to commercial companies adjacent to defense: drone manufacturers, flight simulation software vendors, and mapping service providers should audit their security posture immediately, as they may be seen as easier targets than primary defense contractors.
— HackWire Editorial
---
## Related Coverage