logo

Operation CargoTalon : UNG0901 Targets Russian Aerospace & Defense Sector using EAGLET implant.

ID: bddcd493-e618-5be1-9d7b-38608c3c2dbd

STIX ID: report--bddcd493-e618-5be1-9d7b-38608c3c2dbd

Feed Name: Seqrite Blog

Threat Score
82/100

Date Published: 2025-07-23

Date Updated: 2026-04-30

Author: Subhajeet Singha

...
...

SEQRITE Labs reports a targeted spear-phishing campaign against the Russian aerospace sector that delivered an EAGLET DLL implant via malicious EML/LNK attachments; the implant extracts a decoy XLS, executes via rundll32, establishes HTTP C2 communication (185.225.17.104) using a custom user-agent, and provides shell, download, and exfiltration capabilities. The report includes detailed technical analysis, IOCs (file hashes, filenames, C2 IP), MITRE ATT&CK mappings, and attribution ties to the Head Mare actor family.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.