Pro-Ukraine Hacktivist Group Hacking Cat Evolves to Destructive Malware
The pro-Ukraine hacktivist group Hacking Cat has shifted from defacements and data leaks to deploying destructive malware like ransomware and wipers against Russian targets.

The pro-Ukraine hacktivist collective known as Hacking Cat has significantly escalated its cyber operations, moving beyond website defacements and data leaks to deploy more destructive malware, including ransomware and data-wiping tools, against Russian entities. This evolution, detailed by Russian cybersecurity firm Kaspersky, indicates a growing sophistication and intent to cause substantial disruption.
Kaspersky researchers identified two primary malware families used in attacks attributed to Hacking Cat: Gorilla RAT, a previously unknown remote-access tool, and Monkey Ransomware. Gorilla RAT allows attackers to tunnel network traffic, providing remote access to systems within a victim's network. Monkey Ransomware, as its name suggests, encrypts data and appends the .monkey extension to affected files. These tools were often deployed after attackers gained an initial foothold by exploiting vulnerabilities in Microsoft Exchange servers.
The Monkey Ransomware malware first appeared in late summer or early fall of 2025. Attackers have since been observed rapidly developing and deploying numerous variants, written in different programming languages. This accelerated development cycle has led researchers to speculate that generative AI might have been used to assist in creating or modifying the malware, or that the group is actively experimenting with its capabilities.
Hacking Cat has been actively targeting Russian organizations since approximately February 2024. The shift towards destructive attacks became apparent by the summer of 2025. The group has also been observed collaborating with other Ukraine-linked hacktivist organizations. For instance, in March, Hacking Cat and the Cyber Anarchy Squad claimed responsibility for breaching a contractor working for Rosatom, Russia's state nuclear energy corporation. In June, Hacking Cat partnered with the Ukrainian Cyber Alliance for a destructive attack against Donbassteploenergo, a state-owned heating provider in Russian-occupied parts of Ukraine.
Kaspersky's report also highlights a concerning trend of shared custom-built tools and identical infection chains among different hacktivist groups. This overlap suggests a common developer or a small group of developers may be creating and distributing malware to multiple operations, making attribution significantly more challenging. During a joint operation with the Ukrainian Cyber Alliance, for example, hackers used Nemo Wiper, a malware designed to destroy data and disrupt infrastructure rather than extort ransom payments.
Despite the findings, Hacking Cat has publicly disputed some of Kaspersky's attributions. In a Telegram statement, the group acknowledged ownership of some tools but denied creating the ransomware variants, accusing Kaspersky of misattributing tools from unrelated groups and criticizing the firm's reverse-engineering efforts.
The increasing use of sophisticated and destructive tools by hacktivist groups like Hacking Cat represents a significant escalation in the cyber dimension of the ongoing conflict. The ability to deploy custom malware, potentially aided by AI, and the shared infrastructure among these groups pose a growing challenge for defenders seeking to identify and mitigate threats.