{"id":2902,"date":"2026-09-16T17:34:55","date_gmt":"2026-09-16T17:34:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2902"},"modified":"2026-09-16T17:34:55","modified_gmt":"2026-09-16T17:34:55","slug":"three-threat-groups-target-russian-enterprises-with-backdoors-ransomware-and-wipers","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2902","title":{"rendered":"Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers"},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhMMZZrs8eh-baUC-73E9tejQYA0JZzWyoElUJGhCi0N4_f2EzmPPhQW3xY0kmNZv775T26ywu4czdta-vHaLp1gaI03eqho2SSe3riHMZP8hLTrU1ETnIv-k1ywOpnBFvbkyQJNZt7F4Xx4NndvvS8esTt1jzaCdeN9JZNkNB8sBU1vytibSRAjMsLZzc6\/s1700-nu-rw-lo-l85-e365\/russian-groups.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Enterprises in Russia have emerged as the target of three threat activity clusters tracked as <strong>NightEagle<\/strong>, <strong>Hacking Cat<\/strong>, and <strong>Toy Ghouls<\/strong>, according to multiple reports from Kaspersky.<\/p>\n<p>The cybersecurity vendor said it has <a href=\"https:\/\/securelist.com\/tr\/nighteagle-apt-ghostcontainer-and-tunneling\/121323\/\" target=\"_blank\">identified attacks<\/a> mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.<\/p>\n<p>\u00abIn most incidents, the attackers used compromised valid credentials to gain access to corporate VPNs,\u00bb Kaspersky said in an analysis published today. \u00abVPN connections originated from IP addresses in the Russian segment linked to Cloudflare WARP tunnels, as well as from IP addresses associated with European virtual infrastructure providers.\u00bb<\/p>\n<p>The attacks, as highlighted in July 2025, involve the deployment of GhostContainer, a known modular backdoor that grants the operators complete access to a victim&#8217;s Microsoft Exchange Server, as well as run arbitrary code, perform file operations, and load additional modules.<\/p>\n<p>To sidestep detection, the malware masquerades as a common server component to blend in with regular operations. It can also function as a traffic redirection or tunnel. Prior attacks involving the malware have targeted a government agency and a high-tech company located in Asia.<\/p>\n<p>\u00abIt incorporates components from several open-source projects, including the Neo-reGeorg tunnel, an exploit for the CVE-2020-0688 vulnerability, and the GhostWebShell class from the ysoserial utility,\u00bb Kaspersky explained. \u00abAll of these components are publicly available on GitHub.\u00bb<\/p>\n<p>The exact method used by the attackers to deliver GhostContainer to Microsoft Exchange servers is unknown, although it&#8217;s believed to have involved the extraction of cryptographic keys used by the server from the ASP.NET configuration, followed by overwriting the VIEWSTATE framework parameter, and injecting a payload into it, causing the backdoor to be launched in memory.<\/p>\n<p>To move laterally within the internal network, NightEagle has been observed downloading tunneling tools to redirect network traffic via RDP using <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/developer\/dev-tunnels\/overview\" target=\"_blank\">Microsoft dev tunnels<\/a> and an open-source program called <a href=\"https:\/\/github.com\/V-E-O\/rdp2tcp\" target=\"_blank\">rdp2tcp<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abTo obtain elevated privileges and move laterally through the network, NightEagle exploited various vulnerabilities in Active Directory,\u00bb Kaspersky added. \u00abThe attackers used previously established tunnels to connect to internal infrastructure systems.\u00bb<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>This includes the exploitation of <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2019-0708\" target=\"_blank\">CVE-2019-0708<\/a> (aka <a href=\"https:\/\/support.microsoft.com\/en-us\/servicing\/os\/windows\/2019\/05\/customer-guidance-for-cve-2019-0708-remote-desktop-services-remote-code-execution-vulnerability-may\" target=\"_blank\">BlueKeep<\/a>) to create a local account on the system and add it to the Administrators and Remote Desktop Users groups. Furthermore, the attackers have attempted to impersonate the domain controller by means of a <a href=\"https:\/\/www.trellix.com\/blogs\/platform\/impersonating-the-boss-how-attackers-drain-active-directory\/\" target=\"_blank\">DCSync attack<\/a>.<\/p>\n<p>The end goal is to establish persistence in the victim infrastructure, get password hashes for domain accounts, use long-lived Kerberos tickets to gain legitimate access to target resources, and ultimately break into domain controllers and the victim&#8217;s entire Active Directory infrastructure.<\/p>\n<h3>Pro-Ukrainian Hacking Cat Deploys Gorilla RAT and Monkey Ransomware<\/h3>\n<p>The second group to single out Russian enterprises is Hacking Cat, a pro-Ukrainian hacktivist entity with a history of conducting website defacements and data breaches since February 2024. In recent months, however, the group is said to have shifted tactics and pivoted to encryption and destructive attacks.<\/p>\n<p>\u00abHacking Cat actively collaborates with other hacktivists such as Cyber Anarchy Squad and the Ukrainian Cyber Alliance, which can complicate the attribution of tools to specific attackers,\u00bb Kaspersky <a href=\"https:\/\/securelist.ru\/tr\/hacking-cat\/117062\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>Attacks mounted by the group have weaponized vulnerabilities in Exchange servers (e.g., <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/cve-2021-26855\" target=\"_blank\">CVE-2021-26855<\/a> and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-42897\" target=\"_blank\">CVE-2026-42897<\/a>) to deliver a Go-based remote access trojan dubbed Gorilla RAT, which can tunnel traffic to allow the operator to access the victim&#8217;s internal network.<\/p>\n<p>Once launched, the malware establishes a connection with a remote server, registers the victim, and awaits further instructions that allow it to run arbitrary commands, enumerate processes, gather system information, upload\/download files, and open or close a TCP tunnel.<\/p>\n<p>Also delivered by the threat actor are multiple variants of a ransomware family dubbed Monkey that are written in Rust, .NET, C++, and Golang to target Windows, Linux, and VMware ESXi systems. The earliest Monkey ransomware artifact dates back to late summer 2025. The malware also takes steps to terminate unnecessary processes and inhibit system recovery before starting the encryption process.<\/p>\n<p>\u00abA Rust-based variant of Monkey Ransomware generates a 32-byte key and encrypts the victim&#8217;s files using ChaCha20-Poly1305,\u00bb Kaspersky said. \u00abSome variants do not store the key anywhere, which effectively turns them into full-fledged wiper malware, yet they still leave a ransom note. Other variants, on the other hand, store the key but do not include any contact information in the note.\u00bb<\/p>\n<p>Some of the notable features spread across the other three variants are listed below &#8211;<\/p>\n<ul>\n<li>The .NET variant generates a 32-byte key, sends it to the command-and-control (C2) server, and encrypts victim files using AES-256-CBC. It&#8217;s equipped to escalate privileges and disable Windows recovery mechanisms, extract Microsoft Outlook credentials and send them to the C2 server, delete files with .bak, .backup, .bkf, .bck extensions, and remove itself after execution.<\/li>\n<li>The C++ variant offers similar functionality, but can establish persistence via a scheduled task or a <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/setupapi\/run-and-runonce-registry-keys\" target=\"_blank\">RunOnce<\/a> registry key, clear system logs, disable logging, wipe PowerShell Command History and Windows Command Prompt, bypass AMSI, turn off Event Tracing for Windows (ETW), configure Microsoft Defender exclusions for the encryptor, make Registry modifications to disable Task Manager and Windows Command Prompt, obtain the public IP address by querying api.ipify[.]org and ipapi[.]co, and disable a number of backup, database, and recovery mechanisms, including the Volume Shadow Copy Service (VSS).<\/li>\n<li>The Golang variant, which is mainly used to target Linux and ESXi systems, establishes persistence via a crontab entry, disables SELinux and AppArmor, and attempts to delete volume shadow copies.<\/li>\n<\/ul>\n<p>\u00abThis [Golang] version also includes functionality for removing shadow volume copies, which serves no purpose in Linux and ESXi environments \u2013 a fact that suggests the attackers were careless and likely used AI in developing the toolkit,\u00bb Kaspersky theorized.<\/p>\n<p>Hacking Cat has also been observed teaming up with the <a href=\"https:\/\/securelist.ru\/cyber-anarchy-squad-attacks-with-uncommon-trojans\/111309\/\" target=\"_blank\">Cyber Anarchy Squad<\/a>, another pro-Ukraine hacktivist group, to deliver a different ransomware strain known as ClearWater by means of a batch script. ClearWater is assessed to be distributed under a ransomware-as-a-service (RaaS) to pro-Ukrainian hacktivist crews.<\/p>\n<p>In another collaborative operation with the Ukrainian Cyber Alliance, the threat actor is said to have deployed a wiper malware called Nemo Wiper that overwrites files with random bytes and fills the remaining free disk space with files containing random alphanumeric names and the .lock extension.<\/p>\n<p>\u00abDifferent hacktivist groups are using the same self-written tools in different attacks, including multi-stage infection chains,\u00bb Kaspersky noted. \u00abThis may indicate the existence of a common source for such tools \u2013 for example, a developer or a small group of developers who create, maintain, and modify the malware, which is subsequently used by various hacktivist groups.\u00bb<\/p>\n<p>However, following the publication of the report, Hacking Cat <a href=\"https:\/\/t.me\/hacking_cat\/2517\" target=\"_blank\">posted<\/a> on its Telegram channel that \u00aba couple of the tools are ours, but the lockers are definitely not.\u00bb It has also alleged Kaspersky is attributing tools from completely unrelated actors to them and that it should \u00ablearn to reverse-engineer groups better.\u00bb<\/p>\n<h3>Toy Ghouls Deploys Custom Backdoor for the First Time<\/h3>\n<p>Rounding off the list of groups targeting Russian organizations is Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf), which has moved from using leaked Babuk and LockBit ransomware builders to its own custom GenieLocker ransomware and now to a bespoke backdoor. The financially motivated group is known to be active since 2025.<\/p>\n<p>The backdoor, first detected in July 2026, appears in two variants &#8211;<\/p>\n<ul>\n<li>mqtt-bird-agent 0.1.0, which uses HiveMQ MQTT broker for C2<\/li>\n<li>matrix-bird-agent 0.1.0, which uses Element, a Matrix-based end-to-end encrypted messenger app, for C2<\/li>\n<\/ul>\n<p>\u00abIn this campaign, the attackers use Windows Remote Management (WinRM) to deliver the backdoors and their configuration files to compromised systems,\u00bb Kaspersky <a href=\"https:\/\/securelist.com\/toy-ghouls-new-hivemq-and-element-backdoors\/121270\/\" target=\"_blank\">said<\/a>. \u00abThe group relies on open-source tools such as Evil-WinRM and WinRM-fs to do this.\u00bb<\/p>\n<p>The Bird Agent backdoor can run within an interactive command-line session, as well as set up persistence as a Windows service. Once launched, it looks for a configuration file (\u00abconfig.toml\u00bb) in the same directory from where it&#8217;s located. Alternatively, the full path to the file can be specified via the \u00ab-c\u00bb or \u00ab&#8211;config\u00bb option while running it.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/enterprise-ai-security-a\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhgJrVTpy3T5kJ7VEIro3XfMOmfqDnBU03fYT5CyFWrs2rE9BeQxs835FAS_f1yivzd7mZ7KartftPk4qs8w5Br-WzfYMXruXDQk4FiuXcvSxoA4XH93ipwJJyy2Hbs9jqs-keS9KZhCnQ2YYdv93M51kxJlE862ob-RrrEhP4DEVP3E79zMMPf43e5keoK\/s728-nu-rw-lo-l85-e365\/AI-eBook-d-2.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>The malware then proceeds to read the file and partially encrypts it with a key derived from the victim machine&#8217;s MachineGuid value stored in the Windows Registry so that the configuration is bound to that specific system. The backdoor stops execution if it cannot decrypt the configuration on subsequent runs.<\/p>\n<p>The configuration, depending on the variant used, contains either the cluster identifier used to communicate with the HiveMQ MQTT broker or the Element <a href=\"https:\/\/docs.element.io\/latest\/element-support\/matrix-rooms\/managing-a-room-room-settings\/#advanced\" target=\"_blank\">internal room identifier<\/a> along with the access token necessary to access that room. If this parameter is empty, the backdoor is designed such that it prompts for the token during installation, after which it gets stored.<\/p>\n<p>Once the connection is established, the backdoor proceeds to send system information and issues HTTP GET requests to the HiveMQ broker to fetch commands from the C2 server, execute them via PowerShell in hidden mode (-NonInteractive -NoProfile -Command), and transmit the results back to the server.<\/p>\n<p>The Element variant of Bird Agent is functionally similar to its HiveMQ counterpart, the main difference being that the received commands are executed through the Windows command-line interface (CLI) and send the command output back to the C2 server.<\/p>\n<p>\u00abThe new tools use unconventional channels to communicate with their C2 server: the HiveMQ MQTT broker and the Matrix-based Element messenger,\u00bb Kaspersky said. \u00abThis shift away from publicly available open-source projects toward custom-built tools suggests that Toy Ghouls is working to make its attacks more sophisticated and to evade detection for longer.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2903,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[104,1134,1499,93,54,492,171,3431],"class_list":["post-2902","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-backdoors","tag-enterprises","tag-groups","tag-ransomware","tag-russian","tag-target","tag-threat","tag-wipers"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2902","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2902"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2902\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2903"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}