Russian Aviation Targets Lose GIS Data to Spyware

HeartlessSoul is not just stealing documents. It is collecting GIS, satellite, and GPS files that can expose roads, terrain, engineering networks, and strategic facilities. That turns a normal espionage theft into operational mapping data that can support targeting and route planning. Kaspersky says the group has been active since at least September 2025 and is targeting Russian government agencies, aviation firms, and other industrial entities. The reported access paths include phishing archives, fake aviation software sites, and malware hosted through SourceForge, with the goal of stealing geospatial data from infected systems. The risk is not limited to intelligence loss. Exfiltrated GIS and GPS files can give an attacker the kind of granular infrastructure detail that remains useful long after the initial compromise, including for drone operations or other physical targeting.

Part of the PlainSec briefing for 2026-05-02

Sources