Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2898+ Articles
167+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
NEWS

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky details NightEagle, Hacking Cat, and Toy Ghouls — three distinct clusters hitting Russian organizations with backdoors, ransomware, and wipers.

Dylan H.

News Desk

September 18, 2026
3 min read

Three Distinct Clusters, Three Different Motives

Kaspersky has published research detailing three separate threat activity clusters currently targeting Russian enterprises, each with a distinct motivation, toolset, and methodology: NightEagle (espionage), Hacking Cat (pro-Ukraine hacktivism), and Toy Ghouls (financially motivated cybercrime).


NightEagle (APT-Q-95)

Active since at least 2023, NightEagle has previously been observed hitting Asian government agencies and tech companies, and has now turned its attention to Russian enterprises.

Tradecraft:

  • Uses compromised valid credentials to establish VPN access
  • Routes connections through Cloudflare WARP tunnels and European infrastructure to obscure origin
  • Exploits CVE-2019-0708 (BlueKeep) for privilege escalation
  • Performs DCSync attacks to impersonate domain controllers
  • Extracts cryptographic keys from ASP.NET configurations
  • Uses Microsoft dev tunnels and rdp2tcp for lateral movement

Malware: A modular backdoor called GhostContainer, which grants full access to compromised Exchange Servers and incorporates components from the Neo-reGeorg tunneling tool and ysoserial.


Hacking Cat

A pro-Ukrainian hacktivist group that has shifted tactics since early 2024, moving from website defacement to encryption-based attacks against Russian targets. It collaborates with the Cyber Anarchy Squad and the Ukrainian Cyber Alliance.

Tradecraft:

  • Exploits Exchange vulnerabilities CVE-2021-26855 and CVE-2026-42897

Malware:

  • Gorilla RAT (Go-based) — tunnels traffic, executes commands, manages files
  • Monkey Ransomware — variants written in Rust, .NET, C++, and Golang, targeting Windows, Linux, and VMware ESXi; some variants act purely as wipers
  • ClearWater Ransomware — distributed as ransomware-as-a-service
  • Nemo Wiper — developed collaboratively with the Ukrainian Cyber Alliance

Notably, Hacking Cat has publicly disputed attribution for some of these tools, with the group stating "the lockers are definitely not" theirs — suggesting overlapping or rebranded infrastructure among pro-Ukraine hacktivist clusters.


Toy Ghouls (aka Bearlyfy, Laboo.boo, Feral Wolf)

A financially motivated group active since 2025 that has evolved from deploying leaked Babuk and LockBit ransomware builders toward proprietary tooling.

Tradecraft:

  • Relies on Windows Remote Management (WinRM) for payload delivery
  • Uses the open-source tools Evil-WinRM and WinRM-fs

Malware:

  • Bird Agent backdoor, in two variants:
    • mqtt-bird-agent 0.1.0 — uses HiveMQ MQTT for command-and-control
    • matrix-bird-agent 0.1.0 — uses the Element messenger for command-and-control
  • GenieLocker ransomware — a custom-built encryptor

Why It Matters

The clustering of espionage, hacktivist, and financially motivated activity against the same national target set illustrates how geopolitically charged environments attract a full spectrum of threat actors simultaneously — each pursuing different objectives but often reusing similar initial-access techniques (compromised credentials, exposed Exchange servers, WinRM). Kaspersky's research underscores that defenders in high-tension regions need to account for overlapping campaigns rather than assuming a single adversary profile.

Sources

  • The Hacker News — Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
#Threat Intelligence#Russia#APT#Ransomware#Hacktivism#Kaspersky

Related Articles

NightEagle and Toy Ghouls Join Hacking Cat in Hitting Russian Firms

Kaspersky tracks three distinct clusters — NightEagle, Hacking Cat, and Toy Ghouls — hitting Russian enterprises with backdoors, ransomware, wipers.

4 min read

Pro-Ukraine Hacking Cat Group Deploying New Malware Against Russian Targets

Kaspersky says pro-Ukraine hacktivist group Hacking Cat has moved from defacements to a RAT, ransomware, and a data-destroying wiper.

4 min read

Three China-Linked Clusters Target Southeast Asian

Three threat activity clusters aligned with China jointly targeted a Southeast Asian government organization in a complex, well-resourced espionage...

5 min read
Back to all News