Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Ransomware family

Space Bears Ransomware Decryption & Data Recovery

  • Active
  • High
  • Some versions decryptable

Space Bears is a double-extortion leak-site brand launched in April 2024 and attributed by public research to Phobos/Faust affiliates. Its encryptors carry Phobos hallmarks - info.hta notes and long id[...] extensions - and its victims are mostly small and mid-sized firms in the US and Europe.

First seen
2024-04
File extensions
.id[8位ID-4位版本].[联系邮箱].faust .faust
Ransom notes
info.txt
Affected platforms
Windows

Family profile

File extensions
  • .id[8位ID-4位版本].[联系邮箱].faust
  • .faust
Ransom notes
  • info.txt
  • info.hta
Contact patterns
  • Anonymous mail-provider domains in the note (proton.me, onionmail.org, tuta.io and similar)
  • Per-victim identifier shaped like id[8-char ID-4-digit version]
  • Tor (.onion) leak site with a public countdown page
  • ICQ / Jabber / QQ messaging channels (typical of the Phobos ecosystem)
Aliases / versions
SpaceBears、Spacebears
First seen
2024-04
Status
Active
Operational status
Actively operating
Threat level
High
Affected platforms
  • Windows
Tags
  • Emerging
  • Active
  • Ransomware-as-a-Service
  • Double extortion
  • RDP brute force
  • Phishing
Decryptor
Some versions decryptable

A free decryptor that may apply does exist, but it is not published under the Space Bears name, so applicability has to be proven sample by sample.

Japan's National Police Agency released a free decryption tool for files encrypted by Phobos / 8Base in July 2025, now listed on No More Ransom. The technical basis comes from Cisco Talos: more than a thousand Phobos samples since 2019 share the same hardcoded RSA public key, so holding the matching private key recovers the AES key appended to each encrypted file. Space Bears encryptors are placed in the Phobos/Faust lineage by public research, which makes the tool a realistic option in some cases.

The limits are equally clear: neither the NPA nor No More Ransom names Space Bears or Faust; the tool version, the specific encryptor build and whether the trailing metadata survived all affect the outcome; and the authorities themselves warn the tool is sometimes flagged by antivirus software. Our practice is to identify lineage and build from three to five encrypted files plus the note, trial the tool on offline copies, and only then run at scale - never against original disks.

Sources

Latest activity

  1. Between 3 and 5 September 2026 the leak site named three new victims in 48 hours - US engineering and retail firms plus an Italian clinic - steady output despite law-enforcement pressure on Phobos.

    Sources
  2. The leak site listed a mainland China company, claiming about 2TB of stolen data. The claim is the actors' own and unverified, but it shows Chinese firms are now inside its target set.

    Sources
  3. The site listed the innovative-medicine arm of a large multinational pharmaceutical group. The claim is unconfirmed publicly; listings of large enterprises rose through 2026.

    Sources

Overview

Public information is limited. Leak-site activity is documented, but no independent reverse-engineering report covers a Space Bears encryptor; technical detail is inferred from the Phobos lineage.

S-RM reported that in April 2024 a Faust operator - an affiliate of the Phobos ransomware-as-a-service programme - stood up the Space Bears leak site, which carried eight victims at the time of that report; S-RM added that whether the site would become the shared leak site for the Phobos teams remained to be seen. It is therefore an extortion brand on the Phobos ecosystem rather than a new encryptor, recognisable mainly by its corporate-looking pages and listed "guarantees" of what follows payment - negotiation leverage, not commitments.

The leak-site tracker ransomware.live records roughly 156 named organisations across about 45 countries as of September 2026, concentrated in professional services, technology, manufacturing, healthcare and retail, mostly small and mid-sized firms - a count from a single tracking source, not cross-checked. An international operation in February 2025 seized the 8Base leak site and arrested four Phobos-linked suspects in Thailand, yet the site kept posting, most recently in September 2026.

A listing is not a verified breach: a large European IT services provider named in late 2024 publicly denied in early 2025 that its own infrastructure had been compromised, saying the data came from an unrelated third-party environment. Documented mainland China cases remain scarce; the tracker logged an entry involving a mainland Chinese company in 2026, with earlier entries for firms in Hong Kong and Taiwan - all of them attacker claims.

How to identify it

Extension. No public reverse-engineering report covers a Space Bears encryptor, so the markers below come from the Faust variant its operator runs. Fortinet's analysis of Faust samples shows the original filename kept in full, followed by a string shaped like .id[8-char ID-4-digit build].[contact mailbox].faust; Cisco Talos's comparison of Phobos variants shows the same structure (id[victim ID-build number] + mailbox + brand suffix). Phobos builds differ from crew to crew, so sibling suffixes turning up in a real case is normal - the sample decides.

Ransom notes. Faust drops an info.txt in affected directories plus a pop-up info.hta launched via mshta, a behaviour also documented in CISA's Phobos advisory; the note typically offers free decryption of a few small files and demands a reply within a short deadline.

Attribution caveat. Space Bears is a brand, not one encryptor, and builds differ. The extension alone settles nothing: confirm lineage and build from the metadata structure at the end of encrypted files, because that decides whether any public decryptor is worth trialling.

Infection vectors

Space Bears affiliates use the Phobos access playbook. The joint advisory AA24-060A names two primary vectors: internet-exposed RDP with credential brute forcing, and phishing delivering loaders such as SmokeLoader.

Inside the network: Cobalt Strike for command and control, BloodHound/SharpHound for domain reconnaissance, Mimikatz and Remote Desktop PassView for credentials, RDP for lateral movement. Data is archived to rar or zip and exfiltrated over WinSCP/FTP or Mega-style cloud storage. Negotiation runs over email plus ICQ, Jabber and QQ.

Recent tracking also lists known flaws in edge appliances and remote management software as possible entry points, but nothing authoritative ties them to this brand - test it in forensics rather than assume it.

Encryption behavior

Cisco Talos's analysis of the Phobos family supplies the conclusions that drive any recovery assessment:

  • Algorithms and keys. Custom AES-256 with a fresh random symmetric key per file; each key is wrapped with a hardcoded RSA-1024 public key and written, with metadata, to the end of the file.
  • One shared public key. Across a thousand-plus samples since 2019 every variant used the same RSA public key - precisely why law enforcement could publish a general-purpose decryptor.
  • Size-tiered encryption. Files below roughly 1.5 MB are encrypted in full; larger files only across distributed blocks - which is why database files and virtual disks retain room for structural repair.
  • Destruction and reach. Shadow copies deleted, system recovery and backup disabled, firewall turned off; all connected logical drives encrypted and network shares scanned, so file servers and mapped NAS shares are caught in the same run.

Exfiltration happens before encryption; non-payment leads to staged publication or sale.

Assess before you act

Recoverability assessment

Feasibility is judged sample by sample. We do not pay ransoms and do not negotiate; our work is technical recovery, exposure assessment and attribution.

1) Public decryptor (partially viable). The Phobos/8Base tool from Japan's National Police Agency, listed on No More Ransom, has broad reach because the family shares one RSA public key - but it does not name Space Bears. Success depends on the encryptor build and whether the trailing metadata is intact, so establish lineage first and validate on offline copies.

2) Repairing large, partially encrypted files (depends on the pattern). Files above roughly 1.5 MB are encrypted only across distributed blocks, so MDF/LDF, ibd files and vmdk/vhdx disks often retain large intact regions that page-level extraction and logical rebuilds can exploit; the ratio must be measured on samples.

3) Backups and snapshots. Shadow copies are usually deleted, but offline backups, storage-layer and hypervisor snapshots and cloud version history frequently deliver the highest recovery ratio.

4) Unencrypted copies and log replay. Recycle bins, endpoint caches, ERP archive exports and database transaction logs can support reconstruction or point-in-time replay.

5) Low-level carving. Source data may survive in unallocated clusters - provided writes to the original volumes stop immediately.

6) The exfiltration side. File recovery does not undo the theft. Scope and timeline must be established to drive notification and regulatory obligations, and to rotate affected accounts and keys.

We commit to a verifiable assessment and a clearly bounded recovery scope. We never claim "100% decryption", and no technique guarantees full recovery.

Our response plan

Hit by Space Bears ransomware? What to do

  1. Containment and forensic preservation

    Isolate affected hosts from production networks and storage paths and disable suspect RDP and VPN accounts - but do not reboot or power off. Memory-resident processes, connections and key material are central to the later assessment. Image or snapshot the domain controller, file servers and backup server first, export firewall, RDP logon and Active Directory logs, and preserve three to five encrypted files along with the original info.txt and info.hta.

  2. Lineage determination and encryption analysis

    Space Bears is a brand, so the first task is pinning down the encryptor lineage and build: parse the id[...] structure and mailbox segment in the extension, compare the note text, and above all check whether the metadata block at the end of encrypted files is intact. In parallel, measure the relationship between file size and encryption coverage - confirm that files above 1.5 MB really are block-partial and map which regions were overwritten. This decides whether the path is decryption or structural repair.

  3. Recoverability and exposure assessment

    Trial the public Phobos/8Base decryptor against real samples in an isolated environment, inventory backups, storage snapshots, hypervisor snapshots and unencrypted copies, and run sample repairs on core databases and large files. In parallel, scope the data exposure and its timeline from exfiltration evidence - staging archives, WinSCP or cloud upload records, egress traffic. Deliver a written assessment stating which systems go the decryption route, which need page-level rebuilds and which rely on backup rollback, with expected recovery ranges, timelines and a business restoration order.

  4. Recovery execution and business verification

    All work happens on images or copies with the originals read-only. Restore in business priority order: domain controllers and identity first, then core databases such as ERP and finance, then file shares and mail. For large files, attempt structural repair and mount the result to extract inner data rather than overwriting the original volumes. After each batch, run integrity checks and business-side verification - reconciliation, report comparison, application start-up tests - and record everything in a traceable recovery manifest.

  5. Attribution, hardening and handover

    Reconstruct the full kill chain: which RDP port was exposed, which account was brute forced or reused a password, whether phishing was the origin, where credentials were dumped, and when and how much data left the network. Remove loader and remote-access persistence, rogue accounts and scheduled tasks; reset credentials domain-wide; move RDP behind a jump host or VPN with mandatory multi-factor authentication; rebuild backups to a 3-2-1 design with immutable copies. Close with an incident report, an exposure statement and a formal handover checklist.

Risk warning

What not to do

  • Do not reboot or power off affected hosts - losing memory-resident processes, connections and key material removes the basis for both forensics and any decryption feasibility call.
  • Do not delete or overwrite info.txt, info.hta or the encrypted samples, and do not rush an antivirus clean-up. The id[...] string in the extension and the metadata at the end of each file are the only way in for lineage determination and decryption attempts.
  • Do not run downloaded "Space Bears / Phobos decryptors" against original disks; a mismatched build can destroy the trailing metadata and close off an otherwise viable path. Trials belong on copies.
  • Do not format, reinstall or rebuild RAID sets and storage pools - that permanently removes the option of low-level carving.
  • Do not reconnect backup tapes, external drives or the backup server to a network that has not been cleaned; the operators actively hunt and destroy reachable backups.
  • Do not contact the mailbox in the note or negotiate through the leak site, and do not pay. The site's "guarantees" are not enforceable, and payment neither guarantees a working key nor stops stolen data from being resold or reused.

Emergency response

Data already encrypted? Stop and let an engineer look first

We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.

Related scenarios

Related industries

Similar families

FAQ

Space Bears Frequently asked questions

  • Can files encrypted by Space Bears be decrypted for free?

    Possibly, but not universally. The Phobos/8Base decryptor released by Japan's National Police Agency and listed on No More Ransom is the path worth trying first - Cisco Talos found that Phobos variants have long shared a single RSA public key, which is why the tool has broad reach. It does not name Space Bears, however, and success depends on the encryptor build, whether the trailing metadata survived, and whether files were re-encrypted. The decisive evidence is the sample, not the extension: we determine lineage and build first, validate on isolated copies, and only then decide on a bulk run.

  • How is Space Bears related to Phobos and 8Base?

    Space Bears is not a new encryptor but a leak and pressure brand stood up on the Phobos ecosystem in April 2024. S-RM reported that the crew behind it was a Faust operator affiliated with the Phobos RaaS, and suggested the site might become a shared leak site for the Phobos teams; public reporting never confirmed whether it did. The distinction is operationally useful: analyse the encryption side as Phobos - extension structure, info.hta, trailing metadata, the 1.5 MB size tier - and track the extortion side as Space Bears - countdown, staged publication, sale option.

  • Our files were not encrypted - we were only listed on the leak site. Does that still need handling?

    Yes, and the clock is just as tight. Being listed means data already left the network; encryption only changes the degree of operational disruption, not the compliance and reputational consequences of the exposure. Three immediate actions: establish scope and timeline forensically - which systems, which data, what volume, over which channel; discharge internal notification plus contractual and regulatory obligations accordingly; and rotate affected accounts, keys and API credentials while assessing knock-on effects on customers and suppliers. Note too that leak-site claims are not always sound - organisations have investigated and denied a breach of their own infrastructure, with the data traced to third-party environments - so independent verification comes first.

  • Our SQL Server databases and virtual disks were encrypted - is repair possible?

    Usually yes, and that is exactly the room the Phobos size tier leaves. Cisco Talos found that files below roughly 1.5 MB are fully encrypted while larger ones are encrypted only across distributed blocks. Multi-gigabyte MDF/LDF files, Oracle datafiles, ibd files and vmdk/vhdx disks therefore tend to retain substantial intact regions that page-level extraction and logical rebuilds can use; virtual disks can often be mounted for inner-file extraction once partition and filesystem structures are repaired. The achievable ratio depends on whether headers, page directories or partition metadata were hit, so it must be measured on samples before any scope is promised.

  • What should we do in the first hour after discovery?

    Four things. Isolate: cut affected hosts from production networks and storage paths and disable internet-exposed RDP ports and suspect accounts - but do not power off or reboot. Preserve: image or snapshot the domain controller, file servers and backup server first, and export firewall, RDP logon and Active Directory logs. Keep evidence: retain three to five encrypted files plus the original info.txt and info.hta. Check backups: confirm whether offline backups and storage snapshots still exist and whether they were touched. We run 24/7 emergency response and can usually return an initial lineage assessment and recovery path within an hour of remote access.