🕵️‍♂️ Silent Cyberattack Hits Russian Aerospace Giant — EAGLET Malware Used to Steal Defense Secrets

A silent and dangerous cyberattack has recently hit one of Russia’s most important industries — its aerospace and defense sector. Using a secret digital spy tool called EAGLET, unknown hackers are believed to have stolen sensitive information from high-level targets inside the country. The campaign, now known as Operation CargoTalon, is causing serious concern due to its advanced tactics and hidden techniques.

The hackers targeted a major Russian aircraft company with a fake cargo document that secretly delivered malware. Once opened, the file allowed attackers to spy on the computer and potentially steal files or take control — all without the user’s knowledge.

Fake Cargo Documents Used to Trick Aerospace Staff

The attack focused on employees of Voronezh Aircraft Production Association (VASO) — a top aircraft builder in Russia. The hackers sent emails pretending to be about cargo shipments. These messages included товарно-транспортная накладная (TTN) files, which are official documents used in Russian transport systems. This made the emails look very real and convincing.

🔥 Cyber nightmare unfolds as malware masquerades as hit games like ‘Warstorm Fire’ and ‘Baruda Quest’

Inside these emails was a ZIP file. When opened, it showed a shortcut file (.LNK) that pretended to open an Excel document. But in the background, it launched a PowerShell command that installed the EAGLET malware on the victim’s computer. The Excel file was just a decoy and mentioned a real Russian company called Obltransterminal, which had been sanctioned by the U.S. in early 2024. This clever trick helped to make the attack seem even more believable.

EAGLET Malware: A Digital Spy Hiding in Plain Sight

Once installed, EAGLET quietly collects details about the infected computer. It then tries to connect to a command-and-control server using the IP address 185.225.17[.]104. From there, it waits for new instructions from the hackers. These commands could tell it to download files, upload stolen data, or give full control of the computer to the attackers.

Although the server is currently offline, security experts explain that the attackers designed EAGLET to act like a hidden doorway for other dangerous tools. It allows hackers to easily install more spyware later without being detected. The malware also shares similarities with another known backdoor called PhantomDL, which has similar spying features and may come from the same group.

💻 AI Turns Rogue—LazyHug Malware Learns Like ChatGPT, Steals Data Silently

Military Sector Also Targeted; Links to Other Hackers Found

Investigators discovered that attackers used EAGLET not only against VASO but also in other operations targeting Russia’s military. These attacks match the patterns of another hacker group called Head Mare, which has a history of spying on Russian government and military networks. The file names and technical style used in Operation CargoTalon are very similar to previous attacks from this group.

In a separate operation, a different hacking team named UAC-0184 (Hive0156) launched a fresh wave of cyberattacks targeting Ukrainian systems. Their weapon of choice is Remcos RAT, a remote access tool that allows attackers to spy on and control infected machines. The group used shortcut and PowerShell files that downloaded Hijack Loader malware, which then launched the Remcos RAT tool.

Some of these fake files included Ukrainian military-themed decoys, suggesting that these hackers are focusing heavily on defense targets and may soon expand their reach.

T U Deshmukh
T U Deshmukh is the leading voice on the subject of Jobs, AI, Data and layoffs and she regularly contributes a column on Jobs for Newsinterpretation.

TOP 10 TRENDING ON NEWSINTERPRETATION

2 suspects charged in Oklahoma ATM hacking scheme that used malware to dispense cash

Two Venezuelan nationals have been charged with federal crimes...

Heated debate erupts after Epstein files release and claims Iran tensions shift attention

A heated debate broke out on a television news...

Missile interceptions over Dubai unsettle the city’s long-promoted image of safety

Dubai has long promoted itself as a peaceful oasis...

United states leads dismantlement of one of the world’s largest hacker forums — DOJ

The Department of Justice announced today the seizure of...

Iran-linked hackers ramp up DDoS and malware attacks amid rising tensions

Iran has escalated its response to recent military strikes...

Fresh Epstein disclosures renew scrutiny over Joichi Ito’s role in Japan’s $400M startup project

Fresh disclosures connected to Jeffrey Epstein have once again...

Iran TV Live sports feed abruptly cut as alleged hack airs Trump and Netanyahu

A dramatic video clip circulating online has sparked global...

US and Israel deploy AI and low cost Lucas drones in Iran strike as cyberattacks disrupt defenses

A dramatic joint military operation by the United States...

Newly released US documents expose Jeffrey Epstein’s role in Israel–Ivory Coast security talks

Newly released documents from the United States have drawn...