06/17/2026
This week, DefendEdge's CTI department analyzed HeartlessSoul, a cyber-espionage group targeting Russian government agencies and organizations in the aviation sector. The group's operations focus on collecting geospatial intelligence, including GIS files, terrain models, GPS-related data, and other sensitive information that could provide strategic insight into critical infrastructure and operations.
HeartlessSoul leverages phishing emails, spoofed aviation-themed websites, and trusted platforms such as SourceForge to distribute trojanized software installers. Once executed, the malware establishes persistence through a multi-stage infection chain, deploying a JavaScript-based RAT to conduct surveillance and exfiltrate valuable data from compromised systems.
Stay informed with DefendEdge as we continue to track and expose the latest cyber threats!