UNG0901, short for Unknown Group 901, is a threat cluster associated with Operation CargoTalon. The group has been reported targeting Russia’s aerospace and defense sector through spear-phishing activity designed to deploy the EAGLET implant. Available reporting supports characterization of UNG0901 as an advanced persistent threat cluster engaged in targeted intrusion activity against strategically sensitive organizations in the Russian military-industrial ecosystem. High-confidence public details are limited beyond the campaign’s use of spear-phishing for malware delivery and its focus on aerospace and defense entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage campaign (Operation CargoTalon) targeting Russian aerospace/defense, delivering EAGLET backdoor for data exfiltration.
UNG0901 is a threat actor targeting the Russian aerospace and defense sector using the EAGLET malware implant as part of Operation CargoTalon.
UNG0901 is an APT group conducting spear-phishing campaigns against Russia's aerospace and defense sector to deploy custom implants.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.