top of page

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

2 days ago
2 min read



In mid September 2026, cybersecurity research detailed active campaigns by three distinct threat activity clusters targeting Russian commercial and government organizations. The operations, conducted by groups identified as NightEagle, Hacking Cat, and Toy Ghouls, demonstrate a convergence of cyber espionage, pro Ukrainian hacktivism, and financial extortion. The campaigns weaponize valid credentials, Microsoft Exchange vulnerabilities, and specialized remote management tools to gain initial entry and move laterally across corporate networks.  

NightEagle and the GhostContainer Exchange Backdoor

The threat group NightEagle, also tracked as APT Q 95, leverages compromised valid employee credentials to gain initial access to target corporate virtual private networks. Once connected through encrypted Cloudflare tunnels and European virtual infrastructure, the group deploys a modular backdoor known as GhostContainer. This malware masquerades as a legitimate server component to grant operators full control over Microsoft Exchange servers, run arbitrary system commands, and redirect network traffic using tools like Microsoft developer tunnels. NightEagle then exploits Active Directory vulnerabilities and abuses legacy Windows flaws to obtain elevated privileges, steal domain password hashes, and establish persistence across the broader Active Directory domain. 

 

Pro Ukrainian Hacking Cat and Toy Ghouls Operations

The second cluster, a pro Ukrainian hacktivist entity named Hacking Cat, has shifted its tactics from simple website defacements to destructive encryption attacks. Weaponizing unpatched Microsoft Exchange vulnerabilities, the group installs a Go based remote access tool dubbed Gorilla RAT to establish encrypted command tunnels. Working in tandem with allied hacktivist groups, Hacking Cat deploys extortion tools such as Monkey Ransomware and ClearWater ransomware scripts to disrupt targeted internal networks.  


Concurrently, the threat group Toy Ghouls has evolved its operational tradecraft away from public ransomware builders toward custom built attack tools. The group uses Windows Remote Management protocols alongside open source tools like Evil WinRM to deliver its proprietary GenieLocker ransomware and bespoke backdoors directly to compromised systems. To maintain stealthy command channels, these new backdoors utilize non traditional communications platforms, including public HiveMQ MQTT brokers and end to end encrypted Matrix messenger applications. 


Reference

 
 
 

Comments


Address: Office B322, Level 3, Spaces, Platinum Sentral, KL Sentral, 50470 Kuala Lumpur.

  • Facebook
  • Instagram
  • LinkedIn

Hotline+60327224705

© 2025 Vardaan Sdn Bhd. All Rights Reserved.

bottom of page