UNG0901
Aliases: Operation CargoTalon, Unknown-Group-901
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:23:34
Targeted industries: defense-and-aerospace
Targeted regions: country_code:ru
Context
UNG0901 is a cyber-espionage threat actor targeting Russian entities, particularly in the aerospace and defense sectors, utilizing spear-phishing tactics. They deploy the EAGLET backdoor, which exhibits functionalities similar to the Golang-based PhantomDL used by the Head Mare group, including shell, download, and upload capabilities. Notable overlaps in file-naming conventions and targeting strategies further reinforce the connection between UNG0901 and Head Mare.
Reports & references
- seqrite.com — Operation Cargotalon Ung0901 Targets Russian Aerospace Defense Sector Using Eaglet Implant (report)