A targeted campaign, dubbed Operation CargoTalon, has targeted critical infrastructure in the Russian aerospace and defense industry, according to a recent analysis by Seqrite Labs. At the heart of the attack is an advanced backdoor tool called EAGLET, designed to silently extract data and remotely control compromised systems.

The campaign is attributed to yet another unknown but sophisticated threat actor, codenamed UNG0901 (Unknown Group 901).
See also: Hackers install backdoor in WordPress Mu-Plugins
From spear-phishing to full control: How EAGLET works
The attack begins with common but effective spear-phishing methods, using fake logistics documents (known as товарно-транспортная накладная – TTN) and targeting employees of the Voronezh Aircraft Production Association (VASO) – one of the largest aircraft producers in Russia.
Victims receive phishing emails with ZIP files containing shortcut (LNK) files. These execute PowerShell scripts, simultaneously displaying a fake Excel decoy document and triggering the loading of the EAGLET DLL implant.
According to Seqrite, the documents refer to Obltransterminal, a Russian logistics company that has been on the US sanctions list (OFAC) since February 2024, adding an additional layer of geopolitical and economic dimension to the case.
What is EAGLET and why are experts worried?
The EAGLET backdoor operates as channel remote access, collecting system information and connecting the infected computer to a C2 (Command and Control) server, in order to process the HTTP response from the server and extract the commands to be executed on the compromised Windows computer.
See also: Bugs in Gigabyte firmware allow backdoor development
Seqrite's research also revealed commonalities with previous campaigns attributed to another group, known as Head Mare — raising the possibility of collaboration or reuse of tools among APT entities targeting Russian military and technological structures.

The new face of cyberwarfare
The EAGLET case confirms what experts have long been emphasizing: the line between cyberwarfare, state influence , and economic espionage has now disappeared. The fact that Russian state and private entities are being targeted suggests an international actor seeking strategic data for the aerospace industry, logistics, and the armed forces.
What security experts and governments need to know
Operation CargoTalon is a warning to governments, defense industries, and transportation organizations: is cyberespionage no longer a matter of the future, but of the present.
See also: Atomic macOS malware adds backdoor mechanism
Organizations involved in critical supply chains, military projects, or advanced technologies should immediately review their defense infrastructures, prioritizing detection of LNK/Powershell attacks, system segregation, and the use of EDR (Endpoint Detection and Response) solutions with real-time threat intelligence.
Source: thehackernews.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
