ThreatCluster
  • Feed
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

Operation CargoTalon Targets Russian Aerospace & Defense to Deploy EAGLET Implant

Threat Score:
51
GB Hackers
3 days ago
Part of cluster #1343

Overview

Operation CargoTalon Targets Russian Aerospace & Defense to Deploy EAGLET Implant SEQRITE Labs’ APT-Team has uncovered a sophisticated spear-phishing campaign dubbed Operation CargoTalon, targeting employees at Russia’s Voronezh Aircraft Production Association (VASO), a key aerospace entity. The operation leverages malicious attachments disguised as товарно-транспортная накладная (TTN) logistics documents, critical for Russian supply chains. Discovered on June 27 via VirusTotal hunting, the camp...

Continue Reading on Original Site

Related Articles

5 articles
1

2025-07-27 - Cluster AI Daily Threat Brief

ThreatCluster • 6 hours ago

# Daily Threat Intelligence Brief - July 27, 2025 ## Executive Summary Today's threat landscape presents a mix of sophisticated social engineering attacks, evolving ransomware threats, and vulnerabilities in essential services. The **Gozi** malware cluster is particularly noteworthy, with its impact felt across the financial services and healthcare sectors, affecting approximately **1.4 million customers** following a significant data breach at Allianz Life. Additionally, the gaming sector is

Score
76
Read more
2

Allianz Life Insurance Data Breach – 1.4 Million Customers Data at Risk

Cybersecurity News • 3 hours ago

Major U.S. insurance provider Allianz Life Insurance Company confirmed on Saturday that hackers compromised the personal information of the “majority” of its 1.4 million customers following a sophisticated cyberattack on July 16, 2025. The breach, disclosed in a mandatory filing with Maine’s attorney general, targeted a third-party, cloud-based customer relationship management (CRM) system used by […]

Score
74
Read more
3

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk

Finextra Security • 15 hours ago

From Friction to Function: Optimising Onboarding in an Age of AML, AI and Rising Risk Join this webinar, hosted in association with nCino, to the challenges of commercial onboarding, particularly in the context of increasing regulations like the EU AML Directive and an emphasis on the importance of data strategy, AI, and streamlining Client Lifecycle Management (CLM). How can banks scale AML compliance in an increasingly complex and high-risk environment without compromising the commercial clien

Score
68
Read more
4

Microsoft Patches ‘ToolShell’ Zero-Days Exploited to Hack SharePoint Servers

SecurityWeek • 5 days ago

Microsoft has started releasing updates to fix the exploited SharePoint zero-days tracked as CVE-2025-53770 and CVE-2025-53771.

Score
68
Read more
5
Allianz Life confirms data breach impacts majority of 1.4 million customers

Allianz Life confirms data breach impacts majority of 1.4 million customers

BleepingComputer • 12 hours ago

Allianz Life confirms data breach impacts majority of 1.4 million customers Lawrence Abrams July 26, 2025 02:00 PM 0 Insurance company Allianz Life has confirmed that the personal information for the "majority" of its 1.4 million customers was exposed in a data breach that occurred earlier this month. "On July 16, 2025, a malicious threat actor gained access to a third-party, cloud-based CRM system used by Allianz Life Insurance Company of North America (Allianz Life)," an Allianz Life spokesper

Score
67
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

IP ADDRESSES
185.225.17.104
188.127.254.44
FILE PATH
C:\ProgramData\MicrosoftAppStore directory for persistence.
COMPANIES
AMD
Adobe
Amazon
Apple
Cisco
INDUSTRIES
Aerospace
Education
Logistics
Nuclear
ATTACK TYPES
Phishing
COUNTRIES
Germany
Romania
Russia
VULNERABILITIES
DDoS
DoS
Zero-Day
PLATFORMS
AWS
Android
Apache
Azure
Container
SECURITY VENDORS
Cloudflare
Kaspersky
APT GROUPS
Head Mare
Hezb
Sea Turtle
TA505
MITRE ATT&CK
Masquerading
Phishing
RANSOMWARE
AnDROid
Cmd
Sanctions
Trojan
Zlader
MALWARE
Dark
Lumma Stealer
IP ADDRESSES
185.225.17.104
188.127.254.44
ARTICLE INFORMATION
Article #4446
Published 3 days ago
GB Hackers