Russian Enterprises Under Attack by Three Cyber Threat Groups Using Backdoors, Ransomware, and Wipers
Three threat groups, including NightEagle, Hacking Cat, and Toy Ghouls, are targeting Russian enterprises with advanced techniques such as backdoors, ransomware, and wipers. The attacks leverage vulnerabilities, open-source tools, and lateral movement to compromise infrastructure and deploy malware like GhostContainer, Gorilla RAT, and Monkey Ransomware.
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.
The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
*** END OF TRANSMISSION ***