UNG0901, identified by researchers as Unknown-Group-901 and also operating under the aliases Operation CargoTalon and HEAD MARE, emerged in mid-October 2023 as a pro-Ukrainian threat actor. The group’s primary motivation is to conduct cyber espionage against Russian and Belarusian entities, aiming to support Ukraine's strategic interests. This threat actor is characterized by its consistent use of spear-phishing campaigns that often exploit vulnerabilities in widely used software, and the deployment of custom malware families such as PhantomDL, EAGLET, and PhantomCore, predominantly targeting the aerospace and defense sectors.