Uptime Hamster: 10d 14h 3mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza UNG0901

UNG0901

0 incidentes 0 paises 0 sectores apt UA Ultimo: -
Aliases: Unknown-Group-901, Operation CargoTalon, cargotalon, eaglet implant, headmare, phantomc2, phantomcore, phantomocx, phantomproxylite, phantomremote, ung0901
Ver en IntelTracker → APTTrail →
UNG0901, identified by researchers as Unknown-Group-901 and also operating under the aliases Operation CargoTalon and HEAD MARE, emerged in mid-October 2023 as a pro-Ukrainian threat actor. The group’s primary motivation is to conduct cyber espionage against Russian and Belarusian entities, aiming to support Ukraine's strategic interests. This threat actor is characterized by its consistent use of spear-phishing campaigns that often exploit vulnerabilities in widely used software, and the deployment of custom malware families such as PhantomDL, EAGLET, and PhantomCore, predominantly targeting the aerospace and defense sectors.

Aliases del actor

Unknown-Group-901Operation CargoTaloncargotaloneaglet implantheadmarephantomc2phantomcorephantomocxphantomproxylitephantomremoteung0901

Actores similares

cargotalonactor · 1Operation ForumTrollapt · 0Operation Ghoulapt · 0Operation Epic Manchegoapt · 0unknown ransomware groupransomware · 0lockbit3ransomware · 2016lockbit2ransomware · 1002incransomransomware · 832dragonforceransomware · 580thegentlemenransomware · 504
Tecnicas MITRE
T1059.001 - PowerShell, T1090.003 - Multi-hop Proxy, T1105 - Ingress Tool Transfer, T1140 - Deobfuscate/Decode Files or Information, T1204.001 - Malicious Link, T1071.001 - Web Protocols
CVEs relacionadas
CVE-2025-55182
Tipo
apt
Pais origen
UA
Motivacion
-
Impacto
16
Actualizado
Tue, 03 Fe