Geospatial Data Theft Reframes Espionage Risk

The real target is not ordinary business files. This campaign goes after GIS files, terrain models, and GPS data, so a compromise can reveal where assets are, how operators see the battlespace, and what intelligence capability they have. Kaspersky attributes the HeartlessSoul activity to phishing, malvertising, fake download domains, and a planted SourceForge project that masqueraded as aviation software and utilities. The reported targets are aerospace and drone operators, with current collection focused on Russian government and enterprise systems. That changes the threat model for geospatial teams. Losing these files can expose operational location data that helps an adversary reconstruct coverage and infer intelligence workflows long after the initial intrusion.

Part of the PlainSec briefing for 2026-05-12

Sources