AUTO-UPDATED

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Kaspersky researchers have identified three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—actively targeting Russian enterprises with sophisticated backdoors, ransomware, and advanced lateral movement techniques.

Key Points

  • NightEagle (APT-Q-95) utilizes the GhostContainer modular backdoor to gain persistent access to Microsoft Exchange Servers and exploit Active Directory vulnerabilities.
  • Hacking Cat, a pro-Ukrainian hacktivist group, has pivoted from website defacement to deploying Gorilla RAT and various Monkey ransomware strains across Windows and Linux systems.
  • Toy Ghouls has transitioned from using leaked ransomware builders to deploying a custom "Bird Agent" backdoor that leverages MQTT brokers and Matrix-based messaging for command-and-control.
  • Attackers are increasingly using legitimate tools like Cloudflare WARP tunnels, Microsoft dev tunnels, and open-source utilities to evade detection and maintain network persistence.
  • The campaigns involve complex infection chains, including the exploitation of known vulnerabilities like BlueKeep (CVE-2019-0708) and various Microsoft Exchange flaws.

Why it Matters

These coordinated campaigns demonstrate a significant escalation in the sophistication of cyberattacks targeting Russian infrastructure, shifting from simple hacktivism to persistent, multi-stage espionage and destructive operations. The reliance on custom backdoors and unconventional communication channels highlights a growing trend of threat actors evolving their toolkits to bypass traditional security defenses.
Internet Published by info@thehackernews.com (The Hacker News)
Read original