Download Privacy Needle App

Type to search

Cybersecurity

Three Threat Groups Target Russian Enterprises with Malware and Ransomware

Share

Kaspersky researchers have identified three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—carrying out diverse cyberattacks against Russian enterprises, ranging from stealthy backdoor deployments to destructive wiper malware and ransomware.

The identified groups employ a wide array of tactics, including the exploitation of Microsoft Exchange servers, the use of compromised VPN credentials, and the deployment of bespoke command-and-control (C2) mechanisms to evade detection.

NightEagle Targets Exchange Servers

The first cluster, tracked as NightEagle (also known as APT-Q-95), has been active since at least 2023. According to Kaspersky, these attackers frequently gain initial access to corporate networks by using compromised valid credentials to access virtual private networks (VPNs). These connections have been traced back to IP addresses linked to Cloudflare WARP tunnels and various European virtual infrastructure providers.

A primary tool used by NightEagle is GhostContainer, a modular backdoor designed to provide complete access to Microsoft Exchange Servers. Once deployed, the malware can run arbitrary code, perform file operations, and load additional modules while masquerading as a legitimate server component to blend in with normal operations.

The group has been observed using various open-source components to facilitate its operations, including the Neo-reGeorg tunnel and exploits for CVE-2020-0688. To move laterally within a victim’s network, NightEagle has utilised tools such as Microsoft dev tunnels and rdp2tcp to redirect traffic via remote desktop protocol (RDP). The group also targets Active Directory infrastructure, exploiting vulnerabilities such as CVE-2019-0708 (commonly known as BlueKeep) to escalate privileges and attempt domain controller impersonation via DCSync attacks.

Hacking Cat and Hacktivist Operations

The second cluster, Hacking Cat, is a pro-Ukrainian hacktivist entity that has shifted from simple website defacements to more destructive encryption-based attacks. The group often collaborates with other hacktivist collectives, including the Cyber Anarchy Squad and the Ukrainian Cyber Alliance, which complicates the precise attribution of specific tools.

Hacking Cat weaponises vulnerabilities in Exchange servers to deliver the Gorilla RAT, a Go-based remote access trojan (RAT) that enables attackers to tunnel traffic and access internal networks. Additionally, the group deploys multiple variants of the Monkey ransomware family, written in Rust, .NET, C++, and Golang. While some versions of Monkey act as traditional ransomware, certain variants do not store decryption keys, effectively functioning as wiper malware designed to destroy data rather than extort it.

Following the release of the Kaspersky report, Hacking Cat disputed certain findings on Telegram, claiming that while they own some of the tools, the ransomware (lockers) used in the attacks belong to other actors. The group also alleged that Kaspersky had inaccurately attributed tools from unrelated entities to them.

Toy Ghouls Deploys Custom Backdoors

The third group, Toy Ghouls (also identified as Bearlyfy, Laboo.boo, and Feral Wolf), has evolved from using leaked ransomware builders to developing its own custom malware. This financially motivated group, active since 2025, has recently introduced bespoke backdoors to enhance its sophistication.

The new backdoors, identified as mqtt-bird-agent and matrix-bird-agent, utilise unconventional communication channels for their C2 infrastructure. One variant uses the HiveMQ MQTT broker, while the other uses the Matrix-based Element messenger app to facilitate encrypted communications. This shift away from standard open-source projects suggests an intentional effort to evade traditional security monitoring by using non-standard protocols for command execution and data exfiltration.

Toy Ghouls typically uses Windows Remote Management (WinRM) and open-source tools like Evil-WinRM to deliver these backdoors to compromised systems.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.