Cyber Threat Actor: Spacebears
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
1 incident |
|---|
Profile
Spacebears is a threat actor referenced in open-source reporting under that exact alias and has been described as a ransomware group. The name Spacebears appears in the ransomware.live database as the responsible party for a specific incident. No alternative aliases or spelling variations have been linked to this actor in the publicly available sources. The actor’s public profile is limited to the information associated with that single reported event.
On June 10, 2026, Spacebears carried out a ransomware attack against Cattani, a dental equipment manufacturer that was established in 1967 and exports its products internationally. The victim company designs and produces a variety of dental devices used in clinical settings. Reporting from ransomware.live indicated that the incident was disclosed shortly after discovery but did not provide any details regarding the volume of data affected, the extent of encryption, or whether a ransom demand was communicated. This event marks the only confirmed instance in which Spacebears has been identified as the perpetrator of a cyber operation.
Because the reporting characterizes Spacebears as a ransomware group, it is understood that the actor utilizes ransomware malware to compromise victim systems, although the specific malware family or variant employed in the Cattani attack has not been disclosed. No technical details concerning initial access vectors, privilege escalation methods, lateral movement tools, or post‑exploitation tooling have been made public for this actor. Furthermore, no credible sources have attributed Spacebears to any state sponsor, criminal syndicate, or other affiliations, leaving its origins and alliances unknown. Consequently, the actor remains unattributed and its operational methodology is only inferred from the ransomware nature of the observed incident.
The Cattani breach constitutes the sole publicly documented campaign associated with Spacebears, and no additional operations have been linked to the alias in the available open‑source material. As a result, any broader statements about the actor’s typical target sectors, geographic focus, or strategic intentions would exceed the evidence presented here. The profile of Spacebears is therefore confined to the facts of its alias, its classification as a ransomware group, and the June 2026 attack on a dental equipment manufacturer. This concludes the factual overview based solely on the provided source material.
