Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2823+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets
Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets
NEWS

Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets

Kaspersky says pro-Ukraine hacktivist group Hacking Cat has moved from defacements to a RAT, ransomware, and a data-destroying wiper.

Dylan H.

News Desk

September 14, 2026
4 min read

Pro-Ukraine Hacktivists Trade Defacements for Destructive Malware

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, according to a new report from Russian cybersecurity firm Kaspersky. Researchers say the group, active against Russian organizations since around February 2024, began shifting toward data-encryption and data-destruction operations by the summer of 2025 — and has since built out a small arsenal of custom malware to do it.


Summary

FieldDetails
GroupHacking Cat (pro-Ukraine hacktivist collective)
Attributed byKaspersky (Securelist research)
TargetsRussian organizations, incl. a Rosatom contractor and a Donetsk-region heating provider
MalwareGorilla RAT (remote access), Monkey Ransomware (encryption, .monkey extension), Nemo Wiper (data destruction)
Active sinceFebruary 2024
Shift to destructive opsSummer 2025
Notable collaboratorsCyber Anarchy Squad, Ukrainian Cyber Alliance

What Happened

Kaspersky researchers identified two malware families tied to recent Hacking Cat activity: a previously undocumented remote-access tool the firm dubbed Gorilla RAT, and Monkey Ransomware, which encrypts victim data and appends a .monkey extension to affected files. In some intrusions, the group reportedly exploited vulnerabilities in Microsoft Exchange servers to gain an initial foothold before deploying Gorilla RAT, which can tunnel network traffic and give attackers remote access to systems inside a victim's network.

Monkey Ransomware first appeared in late summer or early fall 2025, and Kaspersky observed the group tweaking it over the following months, deploying variants written in different programming languages. Researchers said the unusually rapid pace of development could point to the use of generative AI to help create or modify the malware — or simply that the group had the resources to iterate quickly.

Kaspersky also tied Hacking Cat to Nemo Wiper, a data-destruction tool used in a joint operation with fellow hacktivist group Ukrainian Cyber Alliance. Unlike Monkey Ransomware, Nemo Wiper appears designed to permanently destroy data and disrupt infrastructure rather than extract a ransom payment.

Hacking Cat has pushed back on parts of Kaspersky's attribution. In a statement posted to Telegram, the group said: "A couple of the tools are ours, sure, but the lockers definitely are not," accusing Kaspersky of linking tools used by unrelated groups to Hacking Cat.


Evolution From Defacement To Destructive Attacks

Hacking Cat's activity against Russian organizations dates back to roughly February 2024, when the group's operations centered on website defacements and leaking stolen data — visible, disruptive, but not destructive. By summer 2025, Kaspersky says the group pivoted toward operations built to encrypt and destroy data outright.

That shift has coincided with closer collaboration between Hacking Cat and other pro-Ukraine hacktivist groups:

  • March — Hacking Cat and fellow hacktivist group Cyber Anarchy Squad claimed responsibility for breaching a contractor working for Rosatom, Russia's state nuclear energy corporation.
  • June — Hacking Cat worked with the Ukrainian Cyber Alliance on a destructive attack against Donbassteploenergo, a state-owned heating provider operating in Russian-occupied parts of Ukraine's Donetsk region, deploying Nemo Wiper in the process.

Kaspersky noted that this pattern of collaboration — multiple groups sharing custom-built tools and, in some cases, identical multi-stage infection chains — makes it "significantly more difficult" to attribute individual attacks to a specific threat actor. The overlap could indicate a small group of developers building and maintaining malware that then circulates across several pro-Ukraine hacktivist collectives, rather than each group developing its tools independently.


Why This Matters

Hacking Cat's trajectory mirrors a broader trend across the pro-Ukraine hacktivist ecosystem: groups that started out with low-cost, high-visibility actions like defacements and leak dumps are increasingly adopting the encryption and wiper malware once associated mainly with state-backed actors and organized ransomware crews. The apparent tool-sharing between groups — and the possibility that generative AI is accelerating malware iteration — also complicates attribution for defenders and researchers trying to track who is behind any individual intrusion. For organizations in Russia, and potentially other regions where geopolitically motivated hacktivist activity spills over, that means threat models built around "nuisance" hacktivism may need updating to account for genuinely destructive follow-on capability.


Sources

  • The Record — Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
#Hacking Cat#Hacktivism#Ransomware#Russia#Ukraine#Kaspersky

Related Articles

Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

The pro-Ukrainian hacktivist group Bearlyfy has conducted over 70 cyberattacks against Russian businesses in the past year and is escalating operations...

4 min read

Bearlyfy Hits Russian Firms with Custom GenieLocker

Pro-Ukrainian hacktivist group Bearlyfy has conducted over 70 cyberattacks against Russian companies since January 2025, recently deploying a custom...

4 min read

Gamaredon Expands Ukraine Attacks with New Malware and Cloud Abuse

Russian FSB-linked APT group Gamaredon has mounted 35 distinct spear-phishing campaigns against Ukrainian targets in 2025, deploying an expanded malware...

5 min read
Back to all News