Eagle S is a Russia-linked oil tanker associated with a 2024 Baltic Sea cable-damage incident involving multiple subsea communications links. The vessel has been described as part of Russia’s shadow fleet used to move sanctioned goods through opaque ownership structures. Public reporting tied the ship to damage that triggered scrutiny from Finnish and other European authorities and intensified concern over possible sabotage against critical undersea infrastructure in the Baltic region. Legal proceedings connected to the incident reportedly faced jurisdictional challenges, and publicly available information does not establish with high confidence that the vessel operated as a coherent cyber threat actor or that the cable damage was a deliberate state-directed operation rather than negligence or unsafe seamanship. No corroborated evidence in the available facts supports malware use, network intrusion activity, ransomware operations, or other cyber capabilities attributable to Eagle S itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.