Operation Cargotalon: Targeting Russian Aerospace Defense Using Eaglet Implant

July 24, 2025, 9:04 a.m.

Description

UNG0901, a threat group targeting Russian aerospace and defense sectors, has been discovered conducting a spear-phishing campaign against the Voronezh Aircraft Production Association. The operation, dubbed 'CargoTalon', utilizes a custom DLL implant called EAGLET, which is disguised as a ZIP file containing transport documents. The infection chain involves a malicious LNK file that executes the EAGLET implant, which then establishes communication with a command-and-control server for remote access and data exfiltration. The campaign employs sophisticated tactics, including decoy documents related to Russian logistics operations, and shows similarities with another threat group known as Head Mare. The attackers' motivation appears to be espionage against Russian governmental and non-governmental entities.

Date

  • Created: July 24, 2025, 5:49 a.m.
  • Published: July 24, 2025, 5:49 a.m.
  • Modified: July 24, 2025, 9:04 a.m.

Indicators

  • f6baa2b5e77e940fe54628f086926d08cc83c550cd2b4b34b4aab38fd79d2a0d
  • e12f7ef9df1c42bc581a5f29105268f3759abea12c76f9cb4d145a8551064204
  • c3caa439c255b5ccd87a336b7e3a90697832f548305c967c0c40d2dc40e2032e
  • b683235791e3106971269259026e05fdc2a4008f703ff2a4d32642877e57429a
  • ae736c2b4886d75d5bbb86339fb034d37532c1fee2252193ea4acc4d75d8bfd7
  • a9324a1fa529e5c115232cbbc60330d37cef5c20860bafc63b11e14d1e75697c
  • a8fdc27234b141a6bd7a6791aa9cb332654e47a57517142b3140ecf5b0683401
  • 4d4304d7ad1a8d0dacb300739d4dcaade299b28f8be3f171628a7358720ca6c5
  • 44ada9c8629d69dd3cf9662c521ee251876706ca3a169ca94c5421eb89e0d652
  • 413c9e2963b8cca256d3960285854614e2f2e78dba023713b3dd67af369d5d08
  • 3e93c6cd9d31e0428085e620fdba017400e534f9b549d4041a5b0baaee4f7aff
  • 204544fc8a8cac64bb07825a7bd58c54cb3e605707e2d72206ac23a1657bfe1e
  • 02098f872d00cffabb21bd2a9aa3888d994a0003d3aa1c80adcfb43023809786
  • 01f12bb3f4359fae1138a194237914f4fcdbf9e472804e428a765ad820f399be
  • 188.127.254.44
  • 185.225.17.104

Attack Patterns

  • EAGLET
  • UNG0901

Additional Informations

  • Aerospace
  • Defense
  • Russian Federation