Kaspersky reported that three threat clusters—NightEagle, Hacking Cat, and Toy Ghouls—are targeting Russian enterprises with new persistence, lateral movement, ransomware, wiper, and backdoor capabilities. The campaigns use tools such as GhostContainer, Gorilla RAT, Monkey ransomware, ClearWater, Nemo Wiper, and Bird Agent to compromise Microsoft Exchange, Active Directory, and other enterprise systems. #NightEagle #HackingCat #ToyGhouls #GhostContainer #GorillaRAT #MonkeyRansomware #ClearWater #NemoWiper #BirdAgent #MicrosoftExchange #ActiveDirectory
Keypoints
- NightEagle used compromised VPN credentials to access Russian corporate networks.
- GhostContainer provided full access to Microsoft Exchange servers and supported covert tunneling.
- Hacking Cat deployed Gorilla RAT and multiple Monkey ransomware variants against Windows, Linux, and ESXi systems.
- Hacking Cat also worked with other pro-Ukrainian groups to deliver ClearWater and Nemo Wiper.
- Toy Ghouls introduced custom Bird Agent backdoors using HiveMQ MQTT and Matrix Element for command-and-control.
Read More: https://thehackernews.com/2026/09/three-threat-groups-target-russian.html