Three Threat Groups Target Russian Enterprises with Malware and Ransomware
Share
Kaspersky researchers have identified three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—carrying out diverse cyberattacks against Russian enterprises, ranging from stealthy backdoor deployments to destructive wiper malware and ransomware.
The identified groups employ a wide array of tactics, including the exploitation of Microsoft Exchange servers, the use of compromised VPN credentials, and the deployment of bespoke command-and-control (C2) mechanisms to evade detection.
NightEagle Targets Exchange Servers
The first cluster, tracked as NightEagle (also known as APT-Q-95), has been active since at least 2023. According to Kaspersky, these attackers frequently gain initial access to corporate networks by using compromised valid credentials to access virtual private networks (VPNs). These connections have been traced back to IP addresses linked to Cloudflare WARP tunnels and various European virtual infrastructure providers.
A primary tool used by NightEagle is GhostContainer, a modular backdoor designed to provide complete access to Microsoft Exchange Servers. Once deployed, the malware can run arbitrary code, perform file operations, and load additional modules while masquerading as a legitimate server component to blend in with normal operations.
The group has been observed using various open-source components to facilitate its operations, including the Neo-reGeorg tunnel and exploits for CVE-2020-0688. To move laterally within a victim’s network, NightEagle has utilised tools such as Microsoft dev tunnels and rdp2tcp to redirect traffic via remote desktop protocol (RDP). The group also targets Active Directory infrastructure, exploiting vulnerabilities such as CVE-2019-0708 (commonly known as BlueKeep) to escalate privileges and attempt domain controller impersonation via DCSync attacks.
Hacking Cat and Hacktivist Operations
The second cluster, Hacking Cat, is a pro-Ukrainian hacktivist entity that has shifted from simple website defacements to more destructive encryption-based attacks. The group often collaborates with other hacktivist collectives, including the Cyber Anarchy Squad and the Ukrainian Cyber Alliance, which complicates the precise attribution of specific tools.
Hacking Cat weaponises vulnerabilities in Exchange servers to deliver the Gorilla RAT, a Go-based remote access trojan (RAT) that enables attackers to tunnel traffic and access internal networks. Additionally, the group deploys multiple variants of the Monkey ransomware family, written in Rust, .NET, C++, and Golang. While some versions of Monkey act as traditional ransomware, certain variants do not store decryption keys, effectively functioning as wiper malware designed to destroy data rather than extort it.
Following the release of the Kaspersky report, Hacking Cat disputed certain findings on Telegram, claiming that while they own some of the tools, the ransomware (lockers) used in the attacks belong to other actors. The group also alleged that Kaspersky had inaccurately attributed tools from unrelated entities to them.
Toy Ghouls Deploys Custom Backdoors
The third group, Toy Ghouls (also identified as Bearlyfy, Laboo.boo, and Feral Wolf), has evolved from using leaked ransomware builders to developing its own custom malware. This financially motivated group, active since 2025, has recently introduced bespoke backdoors to enhance its sophistication.
The new backdoors, identified as mqtt-bird-agent and matrix-bird-agent, utilise unconventional communication channels for their C2 infrastructure. One variant uses the HiveMQ MQTT broker, while the other uses the Matrix-based Element messenger app to facilitate encrypted communications. This shift away from standard open-source projects suggests an intentional effort to evade traditional security monitoring by using non-standard protocols for command execution and data exfiltration.
Toy Ghouls typically uses Windows Remote Management (WinRM) and open-source tools like Evil-WinRM to deliver these backdoors to compromised systems.




Leave a Reply