Russian Firms Face Coordinated Cyberattacks from Three Distinct Groups

Three separate threat clusters are actively targeting Russian enterprises, deploying backdoors, ransomware, and destructive tools to disrupt operations and steal data.
Russian enterprises are under fire from three distinct threat groups identified by cybersecurity firm Kaspersky. The attackers, tracked as NightEagle, Hacking Cat, and Toy Ghouls, are using a mix of backdoors, ransomware, and destructive software to compromise corporate networks. This coordinated pressure highlights a significant escalation in threats against the region's business infrastructure.
The most sophisticated of these groups, NightEagle, has been active since at least 2023 and employs advanced techniques to maintain access to victim systems. According to reports from The Hacker News, these actors often enter networks through compromised VPN credentials, leveraging cloud tunneling services to obscure their origins. Their primary objective is to establish deep, persistent control over internal infrastructure rather than just causing immediate disruption.
Advanced backdoors evade standard detection methods
NightEagle deploys a modular backdoor known as GhostContainer to gain full control over Microsoft Exchange servers. This tool allows attackers to execute arbitrary code, manipulate files, and load additional malicious modules while masquerading as legitimate server components. By blending in with normal operations, the malware effectively hides its presence from standard security monitoring tools.
The backdoor is built using publicly available open-source components, including tunneling utilities and known exploit frameworks. This approach reduces the digital footprint of the attack, making it harder for defenders to distinguish malicious activity from routine server maintenance. The exact delivery method remains uncertain, but it likely involves exploiting specific configuration weaknesses to inject the payload directly into memory.
Once inside, the attackers move laterally across the network by exploiting vulnerabilities in Active Directory. They create local administrative accounts and use tunneling tools to redirect traffic, allowing them to access sensitive internal systems. The end goal is to steal password hashes and long-lived authentication tickets, granting them persistent, legitimate-looking access to the entire domain infrastructure.
Hacktivists shift to destructive attack strategies
A second group, Hacking Cat, has shifted its focus from website defacements to more damaging operations. This pro-Ukrainian hacktivist collective, active since early 2024, now deploys encryption and destructive tools against Russian targets. The group often collaborates with other hacktivist entities, which complicates the ability to accurately attribute specific tools and techniques to individual actors.
Hacking Cat weaponizes vulnerabilities in Exchange servers to deliver a remote access trojan called Gorilla RAT. This malware establishes a connection with remote servers and enables operators to tunnel traffic into the victim's internal network. The shift toward encryption and destructive attacks marks a significant change in the group's operational profile, moving beyond symbolic protest into direct operational harm.
Defenders face complex multi-vector threats
The simultaneous activity of these three groups presents a complex challenge for security teams. NightEagle's focus on persistence and deep network access requires rigorous monitoring of internal traffic and authentication events. Meanwhile, Hacking Cat's use of known vulnerabilities demands rapid patching of public-facing servers to prevent initial compromise.
Organizations must assume that sophisticated actors are already probing their perimeters, using a combination of stolen credentials and technical exploits. The reliance on open-source components by these groups means that detection signatures are becoming more common, but the sheer volume of attacks requires robust, layered defenses. Protecting against both high-end state-sponsored techniques and hacktivist disruption requires a comprehensive security strategy.






