CyberSecurity SEE

Three Threat Groups Target Russian Enterprises Using Backdoors, Ransomware, and Wipers

Three Threat Groups Target Russian Enterprises Using Backdoors, Ransomware, and Wipers

Growing Cyber Threats Targeting Russian Enterprises

In recent developments, Russian enterprises have become prime targets for three distinct threat activity clusters identified by cybersecurity firm Kaspersky: NightEagle, Hacking Cat, and Toy Ghouls. Each of these groups has been reported to engage in increasingly sophisticated cyberattacks, employing advanced techniques to breach security measures and compromise sensitive platforms.

Kaspersky’s analysis reveals that NightEagle, also referred to as APT-Q-95, has been active since at least 2023 and is known for utilizing innovative methods for maintaining access and maneuvering within corporate networks. Numerous incidents indicate that attackers are leveraging valid credentials that have been compromised to infiltrate corporate VPNs. Notably, these VPN connections have been traced back to IP addresses linked to Cloudflare WARP tunnels, as well as European virtual infrastructure providers.

The attacks have prominently featured a modular backdoor named GhostContainer, designed to grant hackers comprehensive access to victims’ Microsoft Exchange servers. This malware is capable of executing arbitrary code, performing file operations, and loading additional modules. Furthermore, GhostContainer cleverly conceals itself as a standard server component, effectively masquerading within routine operations to avoid detection. Previous campaigns involving this backdoor have notably targeted a government agency and a high-tech firm in Asia.

Kaspersky elaborates on GhostContainer’s functionality by highlighting its reliance on components derived from various open-source projects, including the Neo-reGeorg tunnel and tools for exploiting vulnerabilities such as CVE-2020-0688. However, the precise delivery method of GhostContainer remains largely unclear, though it likely involved manipulating server configurations to launch the backdoor in memory directly.

As NightEagle continues to navigate internal networks, it has been observed employing tunneling tools to redirect network traffic, specifically using Microsoft dev tunnels and the open-source program rdp2tcp. This method enables attackers to escalate privileges and traverse the network by exploiting vulnerabilities in Active Directory, establishing persistent connections to critical infrastructure systems.

The attackers have specifically exploited the CVE-2019-0708 vulnerability, also known as BlueKeep, to create local accounts and gain elevated privileges. This proactive approach includes attempts to impersonate the domain controller through DCSync attacks, manifesting a broader strategy to infiltrate the victim’s entire Active Directory infrastructure and capture domain account password hashes, thereby gaining legitimate access to essential resources.

Emergence of Hacking Cat and its Evolving Methodology

The second notable group, Hacking Cat, is characterized as a pro-Ukrainian hacktivist entity that has been active since February 2024. While it initially focused on website defacements and data breaches, recent reports indicate a strategic pivot toward more destructive and encryption-based attacks. Their collaboration with groups like the Cyber Anarchy Squad has complicated the attribution of malicious tools used in their operations.

Kaspersky’s findings indicate that Hacking Cat has successfully exploited vulnerabilities in Exchange servers—specifically CVE-2021-26855 and CVE-2026-42897—to distribute a remote access trojan named Gorilla RAT. This trojan enables the operators to establish a connection to the victim’s internal network and execute arbitrary commands. Additionally, the group has released multiple variants of ransomware known as Monkey, coded in various programming languages, targeting systems such as Windows, Linux, and VMware ESXi.

Their innovative ransomware features capabilities like terminating unnecessary processes and inhibiting recovery options prior to initiating file encryption, raising the stakes considerably for victims. Some variants of the Monkey ransomware, notably the Rust-based iteration, exhibit particularly destructive traits by generating encryption keys without storing them, effectively acting as wiper malware in many contexts.

Kaspersky notes that Hacking Cat has coordinated with other hacktivist networks, potentially leading to a common pool of malicious toolsets among different factions. This evolving landscape of cyber threats has prompted the group to assert on their Telegram channel that they do own some tools but are distancing themselves from others mentioned in Kaspersky’s reports.

Toy Ghouls: The Custom Backdoor Innovators

Completing this trifecta of cyber threats is Toy Ghouls, also dubbed Bearlyfy, Laboo.boo, and Feral Wolf. This financially motivated group transitioned from employing leaked ransomware builders, such as Babuk and LockBit, to developing custom malware solutions, marking a significant evolution in their cyber operations.

As of July 2026, Toy Ghouls was observed deploying a bespoke backdoor, distinctively identified in two variants: mqtt-bird-agent and matrix-bird-agent. This malware utilizes Windows Remote Management (WinRM) to infiltrate compromised systems, indicating a clever method of delivering backdoors and configuration files.

The unique characteristic of this malware lies in its method of communication with command-and-control (C2) servers via the HiveMQ MQTT broker and the Matrix-based Element messenger. Such an unconventional choice for C2 communication channels not only suggests sophistication in attack methodology but also reflects efforts to avoid detection by security systems.

Once operational, the backdoor interacts with the system’s configuration files, effectively binding its functions to the specific machine to reinforce persistence. The malware’s capability to execute commands in hidden mode further reinforces Toy Ghouls’ technical expertise in crafting complex infiltration tactics.

In summary, the emergence of these three cyber threat groups underscores a drastic escalation in the landscape of cybercrime targeting Russian enterprises. Their diverse methodologies, coupled with a propensity for collaboration across various factions, illustrates an evolving threat landscape that organizations must reckon with moving forward. As these groups refine their techniques and tools, the imperative for robust cybersecurity measures has never been more critical.

Source link

Exit mobile version