Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Kaspersky reports that three distinct threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are actively targeting Russian enterprises with a mix of backdoors, ransomware, and wipers.

Enterprises in Russia have become the target of three distinct threat activity clusters, identified by Kaspersky as NightEagle, Hacking Cat, and Toy Ghouls. These groups are employing a range of malicious tools, including backdoors, ransomware, and wipers, indicating a multi-faceted and coordinated threat landscape against Russian organizations.
The NightEagle threat actor, known to be active since at least 2023, has been observed using novel techniques for maintaining persistence and moving laterally within victim networks. Initial access is often gained through compromised valid credentials, with attackers leveraging VPN connections that originate from IP addresses associated with Cloudflare WARP tunnels or European virtual infrastructure providers. A key component in these attacks is the GhostContainer backdoor, a modular tool that provides operators with extensive control over compromised Microsoft Exchange Servers, allowing for arbitrary code execution and the loading of additional modules.
To evade detection, GhostContainer masquerades as a legitimate server component and incorporates elements from publicly available open-source projects, including Neo-reGeorg, an exploit for CVE-2020-0688, and the GhostWebShell class. The precise method of delivery to Exchange servers is unclear, but it is believed to involve manipulating ASP.NET configuration to inject a payload into the VIEWSTATE framework, enabling the backdoor to run in memory. Once inside, NightEagle utilizes tunneling tools and exploits vulnerabilities like CVE-2019-0708 (BlueKeep) to achieve privilege escalation and lateral movement, aiming to compromise domain controllers and the entire Active Directory infrastructure.
The second group, Hacking Cat, is a pro-Ukrainian hacktivist entity that has shifted from its previous focus on website defacements and data breaches to encryption and destructive attacks. Collaborating with other hacktivist groups, Hacking Cat weaponizes vulnerabilities in Exchange servers, such as CVE-2021-26855 and CVE-2026-42897, to deploy the Gorilla RAT. This Go-based remote access trojan allows operators to tunnel traffic, execute arbitrary commands, and exfiltrate data from victim networks.
In addition to Gorilla RAT, Hacking Cat is distributing multiple variants of the Monkey ransomware family, written in various languages including Rust, .NET, C++, and Golang, to target Windows, Linux, and VMware ESXi systems. The earliest known artifact of Monkey ransomware dates back to late summer 2025. This malware is designed to terminate critical processes and disable system recovery mechanisms before initiating file encryption.
Kaspersky's analysis highlights that some variants of Monkey Ransomware, particularly the Rust-based one, use ChaCha20-Poly1305 encryption and may function as wipers if the encryption key is not stored, leaving ransom notes without contact information. Other variants, like the .NET version, employ AES-256-CBC, exfiltrate keys to C2 servers, disable recovery mechanisms, and steal Microsoft Outlook credentials. The C++ variant offers similar capabilities, including persistence via scheduled tasks or registry keys, system log clearing, disabling security features like Task Manager and Event Tracing for Windows (ETW), and disabling backup services like Volume Shadow Copy Service (VSS).
The third group, Toy Ghouls, is also actively targeting Russian enterprises, though specific details regarding their tools and methods are less elaborated in this report. The combined efforts of these three distinct threat actors underscore a significant and evolving cyber threat campaign directed at Russian organizations, employing a diverse arsenal of sophisticated attack vectors and malware.