216.73.216.6

Operation Cargotalon: Targeting Russian Aerospace Defense Using Eaglet Implant

· Published 24/07/2025 05:49 · Modified 24/07/2025 09:04

Export JSON

Essential information

Published
24/07/2025 05:49
Modified
24/07/2025 09:04
Tags
2025-07-24 aerospace defense dll implant eaglet espionage head mare logistics russia spear-phishing
Related entities
16 observables, 1 intrusion sets (apt), 1 malware, 3 others

Description

UNG0901, a threat group targeting Russian and sectors, has been discovered conducting a campaign against the Voronezh Aircraft Production Association. The operation, dubbed 'CargoTalon', utilizes a custom called , which is disguised as a ZIP file containing transport documents. The infection chain involves a malicious LNK file that executes the implant, which then establishes communication with a command-and-control server for remote access and data exfiltration. The campaign employs sophisticated tactics, including decoy documents related to Russian operations, and shows similarities with another threat group known as . The attackers' motivation appears to be against Russian governmental and non-governmental entities.

External references