Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UNG0901

Also known as: Operation CargoTalon, Unknown-Group-901, Fancy Bear, YoroTrooper, SturgeonPhisher, Silent Lynx, Unknown Group 0002, tracked as, APT28, Pawn Storm, Fairy Trickster, Rainbow Hyena, Storm-0978, Tropical Scorpius, Crouching Yeti, Berserk Bear, Dragonfly, techniques, as well as victimology, Head Mare, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, including the retail, aviation, insurance industries, UNC961, Prophet Spider, services, other system resources, public key cryptography, one private, the file association, header, metamorphic, Sednit, UNC2596, Scattered Spider, handler, Netshell, magic bytes, the IconEnvironmentDataBlock, mutating code, BOHRIUM, IMPERIAL KITTEN

Description

UNG0901 operates with high technical sophistication and a strong focus on financial gain, targeting organizations that host critical or commercially valuable information. Their operations are centered around delivery of command-and-control backdoors—such as the Golang‑based EAGLET, Mythic-powered Poseidon, and obfuscated MiniJunk—through spear‑phishing campaigns that embed malicious executables inside ZIP archives containing shortcut files. Execution typically relies on PowerShell invoked via rundll32.exe to launch DLL binaries, a technique that bypasses application whitelisting and provides shell access, file transfer, and remote code execution capabilities. Persistence mechanisms span Windows and Linux: on Windows they embed in the registry via GINA, Group Policy objects or by installing firmware‑level implants (SYNful Knock) that load persistent agents at boot. On Linux, attackers disguise desktop shortcut files as PDFs to create cron jobs, enabling long‑term footholds and lateral movement within target networks. The actor also exploits public software vulnerabilities to widen its attack surface: the WinRAR path‑traversal flaw (CVE‑2025‑8088) is used for silent deployment of backdoors, while a legacy Cisco IOS Smart Install vulnerability (CVE‑2018‑0171) allows acquisition of configuration data. Their operations are supported by an extensive set of remote access and persistence tools—Havex RAT, WhisperGate, SnipBot, RustyClaw, EAGLET, Poseidon, MiniJunk, MiniBrowse—often signed with certificates from legitimate authorities (e.g., SSL.com) to evade detection. Overall, UNG0901 demonstrates a blend of espionage and financial motives, utilizing advanced malware, exploitation tactics, and stealth persistence to target multinational corporations and governmental entities across multiple geographic regions.

Goals & Targeting

Targeted Sectors

Financial services
Telecommunications
Defense
Manufacturing
Aerospace
Government
Media
Transportation
Education
Healthcare
Retail
Critical infrastructure
Aviation
Energy
Oil gas
Food agriculture
Construction
Mining
Entertainment
Legal services
Utilities
Hospitality
Information technology

Targeted Countries / Regions

RU
US
BY
KZ
BR
TW
CA
SG
VN
TR
UA
IN
KP
CN
JP
GB
AU
EG

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 3 hours ago

Executive Summary

UNG0901 (also known as APT28/Fancy Bear and Operation CargoTalon) is a financially-motivated cyber‑espionage actor targeting high‑value sectors such as aerospace, defense, finance, telecoms and energy, primarily against Russian entities. They deploy sophisticated supply‑chain‑style attacks—leveraging public vulnerabilities like WinRAR CVE‑2025‑8088 and Cisco IOS Smart Install CVE‑2018‑0171—to stealthily deliver backdoors (EAGLET, Poseidon, MiniJunk) through ZIP archives containing malicious LNK files. The group maintains persistence via firmware implants, SNMP tooling, disguised Linux cron jobs, and DLL hijacking, while exfiltrating data using encrypted channels.

Goals & Targeting

UNG0901’s strategic objectives center on harvesting intellectual property and sensitive data from high‑value industries—especially aerospace, defense, telecoms, finance, and energy—while also securing financial gains through opportunistic ransomware-like payloads (e.g., Conti, Interlock). The attacker focuses on Russian organizations but extends operations globally, including the US, EU states, China, India, and Middle Eastern countries. By combining stealthy supply‑chain and credential theft techniques with high‑impact persistence mechanisms, UNG0901 seeks to maintain long‑term access for continuous intelligence collection.

Enhanced Description

Key Capabilities

  • Denial of Service attacks
  • Cyber espionage against aerospace sector
  • Exploitation of high‑value software vulnerabilities (WinRAR CVE‑2025‑8088, Cisco IOS CVE‑2018‑0171)
  • Silent deployment of backdoors via archived compressed files
  • Persistence through firmware implants (SYNful Knock) and SNMP tooling
  • Targeting financial, manufacturing, defense, logistics and aerospace organizations
  • Spear‑phishing attachments that deliver a ZIP archive containing a malicious LNK file
  • Execution of PowerShell scripts via the shortcut and launch of a DLL backdoor through rundll32.exe
  • Persistent Windows backdoor (EAGLET) providing shell access and file transfer capabilities
  • Linux persistence via disguised .desktop files masquerading as PDFs and cron job scheduling
  • Poseidon backdoor built on Mythic framework for persistence and lateral movement
  • Obfuscated MiniJunk backdoor that hijacks DLL loading by manipulating the DllPath parameter
  • MiniBrowse stealer targeting credentials stored in Chrome and Edge browsers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Defense Evasion
Credential Access
Discovery
Lateral Movement
Command and Control
Exfiltration

ATT&CK Techniques

T1027
T1059.001
T1059
T1064
T1071
T1105
T1110
T1112
T1113
T1115
T1123
T1136
T1140
T1158
T1160
T1185
T1197
T1203
T1218.003
T1218.005
T1220
T1249
T1295
T1542.006
T1555.003
T1563.001
T1584
T1609
T1612
T1651
T1671
T1689
T1659
T1526
T1548
T1543
T1547
T1037
T1557
T1580
T1583
T1595
T1598

Software / Tooling

Havex RAT
WhisperGate
SnipBot
RustyClaw
Mythic agent
EAGLET
Poseidon
MiniJunk
MiniBrowse
PlugX
Cobalt
Winrar
PowerShell
Hook
Conti
Interlock
Payload
systemd
CHARON
MINIBIKE
PhantomCore
PipeMagic
WarLock
ClickFix
Process Hollowing
AppDomainManager
Telegram
GitHub
BITS
Rundll32
Gunra
Nimbus Manticore
Subtle Snail
MSBuild

Campaigns & Victims

UNG0901 operates with a moderate to high operational tempo, executing continuous spear‑phishing campaigns that deliver ZIP archives containing malicious LNK files. The actor frequently exploits known software vulnerabilities to expand their attack surface and maintain persistence across Windows and Linux environments. Victims have historically included large aerospace firms, defense contractors, financial institutions, telecom operators, and energy companies primarily in Russia but also in the US, EU, Asia, and the Middle East. Notable past operations include the 2025 WinRAR CVE‑2025‑8088 exploit campaign and the Cisco IOS Smart Install CVE‑2018‑0171 attack that leveraged firmware level persistence via SYNful Knock implants.

IOC Patterns

  • Alternate Data Stream usage in compressed archives with CVE‑2025‑8088 path traversal vulnerability
  • Hidden malicious files silently deployed during extraction
  • Exploitation of Smart Install feature via CVE‑2018‑0171
  • SYNful Knock firmware implant for persistence
  • SNMP tooling for remote access
  • ZIP archive containing a malicious LNK/PowerShell payload
  • Execution via rundll32.exe to run a DLL backdoor
  • .desktop file disguised as PDF for cron persistence on Linux
  • Digital certificate signing from SSL.com used to sign malware
  • DLL hijacking using DllPath parameter

Recommended Actions

  • Apply patches for CVE‑2025‑8088 (WinRAR) and CVE‑2018‑0171 (Cisco IOS Smart Install) immediately
  • Disable Smart Install or restrict it on Cisco IOS devices until the vulnerability is addressed
  • Monitor network traffic for abnormal SNMP activity, firmware modifications and SYNful Knock patterns
  • Implement endpoint detection and response rules targeting SnipBot, RustyClaw, Mythic agent, Poseidon, MiniJunk variants
  • Block attachment filtering of ZIP archives that contain shortcut files or LNK executables
  • Enforce application whitelisting to prevent rundll32.exe execution of unknown DLLs
  • Log PowerShell activity, alert on anomalous scripts and restrict execution of unsigned code
  • Detect and remediate unexpected cron jobs, desktop shortcuts and .desktop disguised as PDFs
  • Deploy MFA and secure credential storage for critical accounts
  • Use endpoint protection capable of detecting DLL hijacking techniques (DllPath manipulation)

Suggested Tags

UNG0901
Operation CargoTalon
APT28
Fancy Bear
Sednit
Crouching Yeti
Energetic Bear
phishing attachments
shortcut exploitation
PowerShell
rundll32 usage
backdoor
Mythic framework
MiniJunk obfuscation
DLL hijacking
browser credential stealer
SSL.com certificate signing

Confidence Assessment

The available intelligence aggregates multiple independent reports and malware analyses, providing high confidence in the group’s identity, tactics, and objectives. However, gaps remain regarding precise attribution evidence linking all observed tool variants to a single actor and the exact geographic scope of operations beyond Russia. Continuous monitoring is required for evolving exploitation techniques and emerging weaponized payloads.

ATT&CK Techniques

Exfiltration
1 technique
Initial Access
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  2. attack.mitre.org — Cited by web research for: services
  3. attack.mitre.org — Cited by web research for: Process Hollowing
  4. https://malpedia.caad.fkie.fraunhofer.de/details/win.havex_rat — Cited by AI analysis.
  5. https://thehackernews.com/2025/07/cyber-espionage-campaign-hits-russian.html — Cited by AI analysis.

Intel Summary

60

Techniques

51

Tools

0

Campaigns

40

IOCs

0

Observed Data

16

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
UNG0901
Operation CargoTalon
APT28
Fancy Bear
Sednit
Crouching Yeti
Energetic Bear
phishing attachments
shortcut exploitation
PowerShell
rundll32 usage
backdoor
Mythic framework
MiniJunk obfuscation
DLL hijacking
browser credential stealer
SSL.com certificate signing

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.