A cyber-espionage group targeting Russian aerospace with the EAGLET backdoor via spear-phishing.
Analyst brief
UNG0901 (also tracked as Operation CargoTalon) is a cyber-espionage threat actor targeting Russian aerospace and defense entities. The group uses spear-phishing tactics to deploy the EAGLET backdoor, which provides shell, download, and upload capabilities. This backdoor shares functional similarities with the Golang-based PhantomDL tool used by the Head Mare group, and overlapping file-naming conventions reinforce the connection between the two. Defenders should focus on email security and network anomaly detection, and monitor for shared TTPs and file-naming patterns linked to this activity.
UNG0901
Operation CargoTalonUnknown-Group-901
unknown
UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing spear-phishing tactics. They deploy the EAGLET backdoor, which exhibits functionalities similar to the Golang-based PhantomDL used by the Head Mare group, including shell, download, and upload capabilities. Notable overlaps in file-naming conventions and targeting strategies further reinforce the connection between UNG0901 and Head Mare.
Which sectors does the UNG0901 group target, and what is its primary tactic?+
UNG0901 (Operation CargoTalon) is a cyber-espionage threat actor primarily targeting Russian aerospace and defense entities. Its main tactic involves using spear-phishing to deploy the EAGLET backdoor.
What functionalities does the EAGLET backdoor have, and which group is it associated with?+
The EAGLET backdoor provides shell, download, and upload capabilities. This backdoor shares functional similarities with the Golang-based PhantomDL tool used by the Head Mare group.