Also known as: Operation CargoTalon, Unknown-Group-901, Fancy Bear, YoroTrooper, SturgeonPhisher, Silent Lynx, Unknown Group 0002, tracked as, APT28, Pawn Storm, Fairy Trickster, Rainbow Hyena, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Sednit, UNC2596, Scattered Spider, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, BOHRIUM, IMPERIAL KITTEN
UNG0901 operates with high technical sophistication and a strong focus on financial gain, targeting organizations that host critical or commercially valuable information. Their operations are centered around delivery of command-and-control backdoors—such as the Golang‑based EAGLET, Mythic-powered Poseidon, and obfuscated MiniJunk—through spear‑phishing campaigns that embed malicious executables inside ZIP archives containing shortcut files. Execution typically relies on PowerShell invoked via rundll32.exe to launch DLL binaries, a technique that bypasses application whitelisting and provides shell access, file transfer, and remote code execution capabilities. Persistence mechanisms span Windows and Linux: on Windows they embed in the registry via GINA, Group Policy objects or by installing firmware‑level implants (SYNful Knock) that load persistent agents at boot. On Linux, attackers disguise desktop shortcut files as PDFs to create cron jobs, enabling long‑term footholds and lateral movement within target networks. The actor also exploits public software vulnerabilities to widen its attack surface: the WinRAR path‑traversal flaw (CVE‑2025‑8088) is used for silent deployment of backdoors, while a legacy Cisco IOS Smart Install vulnerability (CVE‑2018‑0171) allows acquisition of configuration data. Their operations are supported by an extensive set of remote access and persistence tools—Havex RAT, WhisperGate, SnipBot, RustyClaw, EAGLET, Poseidon, MiniJunk, MiniBrowse—often signed with certificates from legitimate authorities (e.g., SSL.com) to evade detection. Overall, UNG0901 demonstrates a blend of espionage and financial motives, utilizing advanced malware, exploitation tactics, and stealth persistence to target multinational corporations and governmental entities across multiple geographic regions.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UNG0901 (also known as APT28/Fancy Bear and Operation CargoTalon) is a financially-motivated cyber‑espionage actor targeting high‑value sectors such as aerospace, defense, finance, telecoms and energy, primarily against Russian entities. They deploy sophisticated supply‑chain‑style attacks—leveraging public vulnerabilities like WinRAR CVE‑2025‑8088 and Cisco IOS Smart Install CVE‑2018‑0171—to stealthily deliver backdoors (EAGLET, Poseidon, MiniJunk) through ZIP archives containing malicious LNK files. The group maintains persistence via firmware implants, SNMP tooling, disguised Linux cron jobs, and DLL hijacking, while exfiltrating data using encrypted channels.
Goals & Targeting
UNG0901’s strategic objectives center on harvesting intellectual property and sensitive data from high‑value industries—especially aerospace, defense, telecoms, finance, and energy—while also securing financial gains through opportunistic ransomware-like payloads (e.g., Conti, Interlock). The attacker focuses on Russian organizations but extends operations globally, including the US, EU states, China, India, and Middle Eastern countries. By combining stealthy supply‑chain and credential theft techniques with high‑impact persistence mechanisms, UNG0901 seeks to maintain long‑term access for continuous intelligence collection.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UNG0901 operates with a moderate to high operational tempo, executing continuous spear‑phishing campaigns that deliver ZIP archives containing malicious LNK files. The actor frequently exploits known software vulnerabilities to expand their attack surface and maintain persistence across Windows and Linux environments. Victims have historically included large aerospace firms, defense contractors, financial institutions, telecom operators, and energy companies primarily in Russia but also in the US, EU, Asia, and the Middle East. Notable past operations include the 2025 WinRAR CVE‑2025‑8088 exploit campaign and the Cisco IOS Smart Install CVE‑2018‑0171 attack that leveraged firmware level persistence via SYNful Knock implants.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The available intelligence aggregates multiple independent reports and malware analyses, providing high confidence in the group’s identity, tactics, and objectives. However, gaps remain regarding precise attribution evidence linking all observed tool variants to a single actor and the exact geographic scope of operations beyond Russia. Continuous monitoring is required for evolving exploitation techniques and emerging weaponized payloads.
No campaigns linked yet.
No observed data linked yet.
60
Techniques
51
Tools
0
Campaigns
40
IOCs
0
Observed Data
16
Tactics