HomeSecurityHackers target Russian companies with EAGLET backdoor

Hackers target Russian companies with EAGLET backdoor

A targeted campaign, dubbed Operation CargoTalon, has targeted critical infrastructure in the Russian aerospace and defense industry, according to a recent analysis by Seqrite Labs. At the heart of the attack is an advanced backdoor tool called EAGLET, designed to silently extract data and remotely control compromised systems.

EAGLET backdoor Operation CargoTalon

The campaign is attributed to yet another unknown but sophisticated threat actor, codenamed UNG0901 (Unknown Group 901).

See also: Hackers install backdoor in WordPress Mu-Plugins

From spear-phishing to full control: How EAGLET works

The attack begins with common but effective spear-phishing methods, using fake logistics documents (known as товарно-транспортная накладная – TTN) and targeting employees of the Voronezh Aircraft Production Association (VASO) – one of the largest aircraft producers in Russia.

Victims receive phishing emails with ZIP files containing shortcut (LNK) files. These execute PowerShell scripts, simultaneously displaying a fake Excel decoy document and triggering the loading of the EAGLET DLL implant.

According to Seqrite, the documents refer to Obltransterminal, a Russian logistics company that has been on the US sanctions list (OFAC) since February 2024, adding an additional layer of geopolitical and economic dimension to the case.

What is EAGLET and why are experts worried?

The EAGLET backdoor operates as channel remote access, collecting system information and connecting the infected computer to a C2 (Command and Control) server, in order to process the HTTP response from the server and extract the commands to be executed on the compromised Windows computer.

See also: Bugs in Gigabyte firmware allow backdoor development

Seqrite's research also revealed commonalities with previous campaigns attributed to another group, known as Head Mare — raising the possibility of collaboration or reuse of tools among APT entities targeting Russian military and technological structures.

Hackers target Russian companies with EAGLET backdoor

The new face of cyberwarfare

The EAGLET case confirms what experts have long been emphasizing: the line between cyberwarfare, state influence , and economic espionage has now disappeared. The fact that Russian state and private entities are being targeted suggests an international actor seeking strategic data for the aerospace industry, logistics, and the armed forces.

What security experts and governments need to know

Operation CargoTalon is a warning to governments, defense industries, and transportation organizations: is cyberespionage no longer a matter of the future, but of the present.

See also: Atomic macOS malware adds backdoor mechanism

Organizations involved in critical supply chains, military projects, or advanced technologies should immediately review their defense infrastructures, prioritizing detection of LNK/Powershell attacks, system segregation, and the use of EDR (Endpoint Detection and Response) solutions with real-time threat intelligence.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS