SYMBOLCOMMON_NAMEaka. SYNONYMS

UNG0901  (Back to overview)

aka: Operation CargoTalon, Unknown-Group-901

UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing spear-phishing tactics. They deploy the EAGLET backdoor, which exhibits functionalities similar to the Golang-based PhantomDL used by the Head Mare group, including shell, download, and upload capabilities. Notable overlaps in file-naming conventions and targeting strategies further reinforce the connection between UNG0901 and Head Mare.


Associated Families

There are currently no families associated with this actor.


References
2025-07-23SeqriteSathwik Ram Prakki, Subhajeet Singha
Operation CargoTalon : UNG0901 Targets Russian Aerospace & Defense Sector using EAGLET implant.
UNG0901

Credits: MISP Project