# Sophisticated Cyber Espionage Campaign Targets Aviation Industry for Geospatial Intelligence


Kaspersky Lab has uncovered a coordinated espionage campaign targeting aerospace firms and unmanned aircraft operators, revealing how nation-state threat actors are systematically harvesting geospatial data and GPS intelligence to support regional military conflicts.


## The Threat


A cyber espionage group tracked as HeartlessSoul has launched a multi-faceted attack campaign designed to compromise aviation and drone operations companies and exfiltrate sensitive geospatial information systems. The threat actor operates through meticulously crafted phishing and malvertising campaigns that trick employees into downloading what appears to be legitimate aviation software—but is actually malware designed to establish persistent access and steal mapping data, terrain models, and Global Positioning System (GPS) information.


According to Kaspersky Lab's analysis, the group demonstrates "sophisticated" capabilities characteristic of state-sponsored operations rather than cybercriminal enterprises. The campaign exhibits hallmarks of advanced persistent threats (APTs), including:


  • Multi-stage infection chains that progressively escalate access and evade detection
  • Fileless execution techniques that run malicious code directly in memory without writing to disk
  • Targeted data exfiltration focused on geospatial intelligence assets
  • Infrastructure deception including fake software installers and compromised legitimate platforms

  • The primary targets have been aerospace contractors and drone operators, with victims currently concentrated among Russian government entities and commercial enterprises—suggesting the campaign may be connected to ongoing regional military conflicts where accurate mapping and intelligence data prove strategically valuable.


    ## Background and Context: The Geospatial Intelligence Arms Race


    The rise of HeartlessSoul reflects a broader shift in cyber espionage priorities. As military conflicts evolve and precision operations depend increasingly on accurate geospatial information, threat actors are pivoting away from traditional targets like financial data or intellectual property toward mapping intelligence, GPS coordinates, and terrain models that directly support offensive and defensive military operations.


    "With several ongoing regional military conflicts and an increase in interference with global navigation satellite systems (GNSS), geospatial data has become a more common, if not popular, target for some threat groups," Kaspersky Lab noted.


    This trend is not new but is intensifying. In 2024, IntelBroker—a pseudonymous hacker later identified as British national Kai West—claimed responsibility for breaching Space-Eyes, a Miami-based geospatial intelligence company. Though analysts subsequently cast doubt on some of IntelBroker's claims, the breach highlighted the value threat actors place on geospatial data. West was arrested in June 2025, but his activity underscored that both state and non-state actors recognize mapping intelligence as a high-value target.


    The convergence of three factors makes geospatial data particularly attractive:


    1. Military dependence: Modern conflicts rely on accurate mapping for targeting, logistics, and operational planning

    2. Dual-use nature: GPS and GIS data serve both civilian and military purposes, making theft difficult to trace

    3. Persistent value: Unlike stolen financial records, geospatial intelligence remains operationally useful for years


    ## Technical Details: Attack Methodology and Infrastructure


    HeartlessSoul's operational approach combines social engineering, infrastructure deception, and advanced malware techniques to compromise target organizations.


    ### Attack Vector #1: Phishing Campaigns

    The group crafts convincing phishing emails that deliver links to attacker-controlled domains impersonating legitimate aviation software vendors and flight planning tools. These emails target employees at aerospace firms and drone manufacturers, leveraging industry-specific terminology and branding to increase credibility.


    ### Attack Vector #2: Malvertising

    Alongside phishing, HeartlessSoul deploys malvertising campaigns—malicious advertisements placed on legitimate websites—that direct visitors to compromised download pages hosting infected software packages.


    ### Attack Vector #3: Compromised Supply Chain

    In a particularly brazen maneuver, the threat actor created a fake project on SourceForge, a widely-trusted open-source software repository. Users seeking legitimate tools unknowingly downloaded malicious archives, demonstrating the group's willingness to compromise trusted distribution channels.


    ### Infection Chain

    Once executed, the malware initiates a multi-stage infection sequence:


    | Stage | Purpose | Technique |

    |-------|---------|-----------|

    | Stage 1 | Initial access & reconnaissance | Phishing/malvertising delivers loader |

    | Stage 2 | Privilege escalation & persistence | Multi-stage implant installation |

    | Stage 3 | Defense evasion | Fileless execution, in-memory operations |

    | Stage 4 | Data discovery & exfiltration | GIS files, GPS data, terrain models |


    The use of fileless execution—running malware directly in memory rather than writing executable files to disk—significantly complicates detection by traditional antivirus tools and endpoint protection systems.


    ### Data Targets

    The campaign specifically focuses on:


  • Geospatial Information System (GIS) files containing mapped terrain, infrastructure, and geographic boundaries
  • GPS coordinate databases with exact location data for assets and facilities
  • Aeronautical charts and navigation data
  • Intelligence on rival capabilities, suggesting the adversary seeks to map competitors' or enemies' technical infrastructure

  • ## Implications: Who Is Threatened?


    The immediate risk extends beyond the currently targeted Russian aviation sector.


    Aerospace and defense contractors worldwide operating in contested regions face elevated risk, particularly those involved in:

  • Unmanned aerial systems (UAS/drones)
  • Military aircraft development and support
  • Satellite and geospatial imaging services
  • Logistics and supply chain mapping for defense operations

  • Commercial aviation companies and regional airlines serving conflict zones may be inadvertent secondary targets if their infrastructure or routing data becomes militarily relevant.


    Civilian geospatial firms providing mapping services, GPS infrastructure, or terrain modeling to governments or militaries should assume they are on threat actor targeting lists.


    The sophistication and resources evident in HeartlessSoul's operations suggest nation-state sponsorship, likely to support ongoing military activities. This implies the campaign will continue adapting and expanding as long as regional conflicts create demand for geospatial intelligence.


    ## Recommendations for Defenders


    Organizations in aerospace, defense, and geospatial sectors should implement immediate mitigations:


  • Email security: Deploy advanced phishing detection, user authentication verification, and link scanning to block malvertising redirects
  • Endpoint detection and response (EDR): Deploy behavioral analytics to catch fileless attacks and memory-based malware execution
  • Supply chain validation: Verify software downloads through cryptographic signatures and official vendor channels; avoid third-party repositories for critical tools
  • Data classification: Identify and isolate geospatial, GPS, and mapping data; apply enhanced monitoring to access and exfiltration attempts
  • Network segmentation: Isolate systems containing sensitive mapping data from general network traffic
  • Incident response planning: Prepare for data breach scenarios; assume geospatial theft may occur and have containment procedures ready

  • ---


    ## HackWire Analysis


    The emergence of HeartlessSoul represents a fundamental shift in espionage priorities that defenders must recognize and adapt to. For years, cyber threat intelligence has focused on financial data, intellectual property, and credentials. But as military conflicts increasingly depend on precision operations, geospatial intelligence has become as strategically valuable as nuclear secrets—and it's far easier to steal.


    What makes this campaign particularly dangerous is that it exploits a blind spot in conventional cybersecurity. Most organizations and government agencies have mature defenses around financial systems, classified networks, and human intelligence operations. But GIS files, terrain models, and GPS databases often live in less-protected systems because they're classified as "operational support" rather than "top-secret intelligence."


    HeartlessSoul's willingness to compromise SourceForge—a platform trusted by millions of developers—signals that threat actors no longer fear reputational consequences when they attack trusted supply chains. They understand that the window between discovery and exploitation is measured in months, and the intelligence value of one successful breach justifies the eventual exposure.


    For aerospace and defense contractors: assume your geospatial and GPS data is already in the crosshairs. The question is not whether sophisticated adversaries want it, but whether your detection capabilities can catch exfiltration before it happens. Behavioral monitoring, data-loss prevention, and network segmentation around geospatial systems are no longer optional—they're foundational security requirements.


    The pattern also extends to commercial companies adjacent to defense: drone manufacturers, flight simulation software vendors, and mapping service providers should audit their security posture immediately, as they may be seen as easier targets than primary defense contractors.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)