Pro-Ukraine Hacktivists Trade Defacements for Destructive Malware
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, according to a new report from Russian cybersecurity firm Kaspersky. Researchers say the group, active against Russian organizations since around February 2024, began shifting toward data-encryption and data-destruction operations by the summer of 2025 — and has since built out a small arsenal of custom malware to do it.
Summary
| Field | Details |
|---|---|
| Group | Hacking Cat (pro-Ukraine hacktivist collective) |
| Attributed by | Kaspersky (Securelist research) |
| Targets | Russian organizations, incl. a Rosatom contractor and a Donetsk-region heating provider |
| Malware | Gorilla RAT (remote access), Monkey Ransomware (encryption, .monkey extension), Nemo Wiper (data destruction) |
| Active since | February 2024 |
| Shift to destructive ops | Summer 2025 |
| Notable collaborators | Cyber Anarchy Squad, Ukrainian Cyber Alliance |
What Happened
Kaspersky researchers identified two malware families tied to recent Hacking Cat activity: a previously undocumented remote-access tool the firm dubbed Gorilla RAT, and Monkey Ransomware, which encrypts victim data and appends a .monkey extension to affected files. In some intrusions, the group reportedly exploited vulnerabilities in Microsoft Exchange servers to gain an initial foothold before deploying Gorilla RAT, which can tunnel network traffic and give attackers remote access to systems inside a victim's network.
Monkey Ransomware first appeared in late summer or early fall 2025, and Kaspersky observed the group tweaking it over the following months, deploying variants written in different programming languages. Researchers said the unusually rapid pace of development could point to the use of generative AI to help create or modify the malware — or simply that the group had the resources to iterate quickly.
Kaspersky also tied Hacking Cat to Nemo Wiper, a data-destruction tool used in a joint operation with fellow hacktivist group Ukrainian Cyber Alliance. Unlike Monkey Ransomware, Nemo Wiper appears designed to permanently destroy data and disrupt infrastructure rather than extract a ransom payment.
Hacking Cat has pushed back on parts of Kaspersky's attribution. In a statement posted to Telegram, the group said: "A couple of the tools are ours, sure, but the lockers definitely are not," accusing Kaspersky of linking tools used by unrelated groups to Hacking Cat.
Evolution From Defacement To Destructive Attacks
Hacking Cat's activity against Russian organizations dates back to roughly February 2024, when the group's operations centered on website defacements and leaking stolen data — visible, disruptive, but not destructive. By summer 2025, Kaspersky says the group pivoted toward operations built to encrypt and destroy data outright.
That shift has coincided with closer collaboration between Hacking Cat and other pro-Ukraine hacktivist groups:
- March — Hacking Cat and fellow hacktivist group Cyber Anarchy Squad claimed responsibility for breaching a contractor working for Rosatom, Russia's state nuclear energy corporation.
- June — Hacking Cat worked with the Ukrainian Cyber Alliance on a destructive attack against Donbassteploenergo, a state-owned heating provider operating in Russian-occupied parts of Ukraine's Donetsk region, deploying Nemo Wiper in the process.
Kaspersky noted that this pattern of collaboration — multiple groups sharing custom-built tools and, in some cases, identical multi-stage infection chains — makes it "significantly more difficult" to attribute individual attacks to a specific threat actor. The overlap could indicate a small group of developers building and maintaining malware that then circulates across several pro-Ukraine hacktivist collectives, rather than each group developing its tools independently.
Why This Matters
Hacking Cat's trajectory mirrors a broader trend across the pro-Ukraine hacktivist ecosystem: groups that started out with low-cost, high-visibility actions like defacements and leak dumps are increasingly adopting the encryption and wiper malware once associated mainly with state-backed actors and organized ransomware crews. The apparent tool-sharing between groups — and the possibility that generative AI is accelerating malware iteration — also complicates attribution for defenders and researchers trying to track who is behind any individual intrusion. For organizations in Russia, and potentially other regions where geopolitically motivated hacktivist activity spills over, that means threat models built around "nuisance" hacktivism may need updating to account for genuinely destructive follow-on capability.