Kaspersky researchers have identified three distinct threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—actively targeting Russian enterprises with sophisticated backdoors, ransomware, and advanced lateral movement techniques.
Key Points
- NightEagle (APT-Q-95) utilizes the GhostContainer modular backdoor to gain persistent access to Microsoft Exchange Servers and exploit Active Directory vulnerabilities.
- Hacking Cat, a pro-Ukrainian hacktivist group, has pivoted from website defacement to deploying Gorilla RAT and various Monkey ransomware strains across Windows and Linux systems.
- Toy Ghouls has transitioned from using leaked ransomware builders to deploying a custom "Bird Agent" backdoor that leverages MQTT brokers and Matrix-based messaging for command-and-control.
- Attackers are increasingly using legitimate tools like Cloudflare WARP tunnels, Microsoft dev tunnels, and open-source utilities to evade detection and maintain network persistence.
- The campaigns involve complex infection chains, including the exploitation of known vulnerabilities like BlueKeep (CVE-2019-0708) and various Microsoft Exchange flaws.