Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
AI-summarised brief · reviewed before publication
Kaspersky identified three threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—targeting Russian enterprises with sophisticated attacks. NightEagle uses GhostContainer, a modular backdoor that infiltrates Microsoft Exchange servers via credential theft and VPN tunneling, then exploits Active Directory vulnerabilities for lateral movement and persistence. Hacking Cat, a pro‑Ukrainian hacktivist group, shifted to ransomware and destructive tactics, deploying Gorilla RAT and Monkey ransomware variants that encrypt data across Windows, Linux, and VMware platforms. These coordinated campaigns exploit publicly available tools and known CVEs to compromise critical infrastructure.
💡 Why It Matters
- · The attacks expose how Russian businesses remain vulnerable to state‑aligned and hacktivist actors, underscoring the need for robust VPN security and rapid patching of Exchange and Active Directory flaws.