• 5 minuti
  • Pubblicato

Russian Enterprises Targeted by Coordinated Cyberattacks Using Custom Malware

Barbara Carminati Autrice di cybersecurity e privacy QWERTYmag

Scritto da Barbara Carminati

Russian Enterprises Targeted by Coordinated Cyberattacks Using Custom Malware QWERTYmag © www.qwertymag.it
Russian Enterprises Targeted by Coordinated Cyberattacks Using Custom Malware © www.qwertymag.it

Three threat groups-NightEagle, Hacking Cat, and Toy Ghouls-are systematically breaching Russian companies with advanced backdoors, ransomware, and wiper malware, according to new research from Kaspersky.

Russian corporate networks are facing a wave of targeted cyberattacks from three separate groups: NightEagle, Hacking Cat, and Toy Ghouls. Each group is using its own set of custom malware, backdoors, and ransomware, with tactics that show a clear shift toward more persistent and destructive operations. Kaspersky's latest research points to a coordinated escalation in both technical complexity and intent.

  • NightEagle: Blending In and Digging Deep

    NightEagle, also known as APT-Q-95, has been active since at least 2023. The group uses a modular backdoor called GhostContainer to break into Microsoft Exchange servers. NightEagle stands out for its ability to hide within normal network traffic, using stolen credentials to access corporate VPNs and masking its activity through Cloudflare WARP tunnels and European virtual servers. Once inside, GhostContainer pretends to be a standard server component, giving attackers full control to run code, move files, and load more modules-all while staying under the radar. This is a particular risk for organizations running on-premises Exchange, since the malware takes advantage of both old and recently patched vulnerabilities. Kaspersky stresses the need for timely security updates and following ACN advisories.

    GhostContainer's toolkit is built from open-source projects like Neo-reGeorg, an exploit for CVE-2020-0688, and the GhostWebShell class from ysoserial. According to Kaspersky, the attackers likely extract cryptographic keys from ASP.NET configs, overwrite the VIEWSTATE parameter, and inject their payloads directly into memory. NightEagle's lateral movement is systematic: the group downloads tunneling tools such as rdp2tcp, exploits Active Directory flaws, and uses CVE-2019-0708 (BlueKeep) to create privileged accounts. Their goal is to establish long-term access, collect password hashes, and compromise domain controllers to take over the entire Active Directory environment.

  • Hacking Cat: From Defacement to Data Destruction

    Hacking Cat, a pro-Ukrainian hacktivist group, has shifted from website defacements and data leaks to full-scale encryption and wiper attacks since February 2024. The group works with others, including Cyber Anarchy Squad and the Ukrainian Cyber Alliance, making attribution and tool tracking more difficult. Their recent attacks exploit Exchange server vulnerabilities (such as CVE-2021-26855 and CVE-2026-42897) to deliver Gorilla RAT, a Go-based remote access trojan that can tunnel traffic, run commands, and steal files. These methods reflect a broader trend of attackers using known flaws in widely used enterprise software-a risk highlighted by the Agenzia per la Cybersicurezza Nazionale in recent alerts.

    Kaspersky подчёркивает, что Hacking Cat значительно затрудняет атрибуцию атак, поскольку группировка использует широкий набор собственных и заимствованных инструментов и часто действует вместе с другими проукраинскими хактивистами.

    The group's attacks have escalated with Monkey ransomware, a family written in Rust, .NET, C++, and Golang, targeting Windows, Linux, and VMware ESXi systems. Some versions act as pure wipers, destroying data without saving encryption keys. Others send keys to command-and-control servers or leave ransom notes with no contact details. The .NET variant is designed to escalate privileges, disable recovery, extract Outlook credentials, and delete itself. The C++ version adds persistence, log wiping, AMSI bypass, and disables backup tools. The Golang variant, aimed at Linux and ESXi, disables SELinux and AppArmor and tries to delete shadow copies-though Kaspersky notes this step is unnecessary in those environments, suggesting possible AI-assisted development.

    Hacking Cat's partnerships have led to more threats: ClearWater ransomware, spread via batch scripts, and Nemo Wiper, which overwrites files and fills disks with random data. Kaspersky notes that several hacktivist groups are using the same custom tools, hinting at a shared developer or toolkit. Hacking Cat, however, disputes some of these attributions, stating on Telegram that "a couple of the tools are ours, but the lockers are definitely not," and accusing Kaspersky of misattribution.

  • Toy Ghouls: Custom Backdoors and Unusual Channels

    Toy Ghouls-also known as Bearlyfy, Laboo.boo, and Feral Wolf-has moved from using leaked ransomware builders to deploying its own GenieLocker ransomware and, more recently, a custom backdoor. First detected in July 2026, the Bird Agent backdoor comes in two forms: mqtt-bird-agent, which uses the HiveMQ MQTT broker for command-and-control, and matrix-bird-agent, which uses the encrypted Element messenger app. The malware is delivered via Windows Remote Management, using open-source tools like Evil-WinRM and WinRM-fs.

    Once installed, Bird Agent reads a configuration file encrypted with a key based on the victim's MachineGuid, tying the malware to that specific system. The backdoor sets itself up as a Windows service and connects to its command server to fetch and run commands-using PowerShell or the command line, depending on the version. This move toward custom tools and less common command channels is a clear attempt by Toy Ghouls to avoid detection and stay inside networks longer. Kaspersky's data shows that Toy Ghouls previously used leaked Babuk and LockBit ransomware before switching to their own malware, reflecting a wider shift from off-the-shelf threats to tailored attack frameworks.

  • Shared Tactics and a Changing Threat Landscape

    All three groups rely on open-source tools, public exploits, and collaborative development. The line between hacktivism and financially motivated crime is increasingly blurred, and there is a clear trend toward multi-stage attacks and tool sharing. Kaspersky's findings echo patterns seen in earlier campaigns, where advanced attackers used zero-day exploits and modular malware to get around even strong defenses.

    Russian enterprises now face organized, persistent attackers using custom malware and every available entry point. The industry's response will need to be just as adaptive, with continuous monitoring and a willingness to question assumptions about attribution and intent. The level of sophistication and persistence in these attacks is a clear warning for any organization relying on legacy defenses.

  • Articoli correlati