Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware and Destructive Wipers
Kaspersky reports NightEagle, Hacking Cat and Toy Ghouls targeting Russian enterprises with VPN compromise, Exchange attacks, GhostContainer and Gorilla RAT backdoors, ransomware and destructive wipers.

Russian enterprises are facing attacks from three separate threat clusters using a combination of compromised VPN credentials, Microsoft Exchange exploitation, custom backdoors, ransomware and destructive wiper malware.
According to research published by Kaspersky, the activity involves groups tracked as NightEagle, Hacking Cat and Toy Ghouls.
While their motivations and techniques differ, the campaigns demonstrate a common focus on obtaining persistent access to enterprise networks, moving laterally through internal infrastructure and compromising high-value systems.
NightEagle has concentrated heavily on VPN access, Exchange servers and Active Directory compromise. Hacking Cat has been associated by Kaspersky with remote-access malware, ransomware and destructive attacks. Toy Ghouls, meanwhile, has expanded from publicly available ransomware builders toward its own ransomware and custom backdoor infrastructure.
Three Threat Clusters at a Glance
| Threat Group | Main Techniques | Malware / Tools | Primary Objective |
|---|---|---|---|
| NightEagle / APT-Q-95 | Compromised VPN credentials, Exchange compromise, AD attacks, tunneling | GhostContainer, Neo-reGeorg, rdp2tcp | Persistence, credential theft and domain compromise |
| Hacking Cat | Exchange exploitation, RAT deployment, encryption and destructive attacks | Gorilla RAT, Monkey ransomware, reported use of ClearWater and Nemo Wiper | Remote access, disruption and destruction |
| Toy Ghouls | WinRM-based deployment, custom C2 and ransomware | Bird Agent, GenieLocker | Persistent access and financially motivated attacks |
The three clusters should not be treated as a single threat operation.
NightEagle Targets VPNs, Exchange and Active Directory
The first group, NightEagle, also known as APT-Q-95, has been active since at least 2023.
Kaspersky reported that in many investigated incidents, attackers obtained initial access using compromised legitimate credentials for corporate VPN services.
The VPN connections originated from infrastructure including Cloudflare WARP-linked addresses in the Russian internet segment and European virtual infrastructure providers.
Using valid credentials can make intrusion detection more difficult because authentication may initially resemble legitimate remote access.
A simplified NightEagle intrusion can look like:
Compromised VPN credentials
↓
Corporate network access
↓
Microsoft Exchange targeted
↓
GhostContainer deployed
↓
Network tunnels established
↓
Active Directory attacked
↓
Credentials and password hashes obtained
↓
Domain infrastructure compromised
GhostContainer Provides Persistent Exchange Access
A major component of NightEagle's toolkit is GhostContainer, a modular backdoor previously associated with attacks against organizations in Asia.
GhostContainer is designed to operate on compromised Microsoft Exchange servers and provides capabilities including:
- Arbitrary code execution
- File operations
- Additional module loading
- Traffic tunneling
- Network redirection
- Persistent remote access
The malware attempts to blend into legitimate server activity by masquerading as a normal server component.
GhostContainer also incorporates components derived from publicly available projects, including Neo-reGeorg, code associated with exploitation of CVE-2020-0688, and the GhostWebShell class from ysoserial.
Kaspersky said the exact mechanism used in the observed incidents to initially place GhostContainer on Exchange servers remains unclear.
Researchers believe the process may involve obtaining cryptographic material from ASP.NET configuration and manipulating the VIEWSTATE mechanism to trigger in-memory execution.
NightEagle Uses Tunnels for Lateral Movement
Once inside an organization, NightEagle creates network tunnels to reach internal systems.
Researchers observed the attackers using Microsoft development tunnels and the open-source rdp2tcp utility to redirect traffic associated with Remote Desktop Protocol.
These tunnels can allow attackers to interact with internal infrastructure through systems they have already compromised.
The group has also exploited weaknesses in Active Directory environments as part of privilege escalation and lateral movement.
One vulnerability associated with the activity is:
CVE-2019-0708 — BlueKeep
NightEagle reportedly used exploitation activity to create local accounts and add those accounts to the:
Administrators
and
Remote Desktop Users
groups.
DCSync Used Against Active Directory
NightEagle has also attempted DCSync attacks.
DCSync abuses Active Directory replication functionality to request credential information in a way that imitates a domain controller.
If an attacker obtains sufficient privileges, the technique can expose sensitive authentication material, including password hashes associated with domain accounts.
NightEagle's broader objective appears to involve establishing long-term access through:
Password hashes
Kerberos authentication
Persistent tunnels
Domain-controller access
The ultimate result can be extensive control over an organization's Active Directory infrastructure.
Hacking Cat Shifts Toward Destructive Operations
The second cluster highlighted by Kaspersky is Hacking Cat, which the company describes as a pro-Ukrainian hacktivist group active since February 2024.
Earlier activity associated with the group included website defacement and data breaches.
Kaspersky says more recent operations have shifted toward encryption and destructive attacks.
The group has also been reported collaborating with other hacktivist organizations, including:
- Cyber Anarchy Squad
- Ukrainian Cyber Alliance
These overlaps make attribution more difficult because tools may be shared between multiple groups.
Exchange Vulnerabilities Used to Deliver Gorilla RAT
Kaspersky associated Hacking Cat operations with exploitation of Microsoft Exchange vulnerabilities including:
CVE-2021-26855
and
CVE-2026-42897
to deploy a Go-based remote-access trojan called Gorilla RAT.
After execution, Gorilla RAT connects to attacker-controlled infrastructure and registers the infected machine.
Operators can then issue commands allowing the malware to:
- Execute arbitrary commands
- Enumerate processes
- Gather system information
- Upload files
- Download files
- Create TCP tunnels
- Close existing tunnels
Its tunneling capabilities can also provide attackers with access to other systems located deeper inside the compromised network.
Monkey Ransomware Targets Windows, Linux and ESXi
Kaspersky also linked Hacking Cat with a ransomware family called Monkey.
Researchers identified multiple implementations written in:
- Rust
- .NET
- C++
- Golang
The variants target a combination of Windows, Linux and VMware ESXi environments.
This cross-platform capability is important because compromising virtualization infrastructure can affect numerous workloads simultaneously.
Rust Variant
The Rust implementation generates a 32-byte encryption key and encrypts files using:
ChaCha20-Poly1305
Some samples reportedly fail to preserve the encryption key.
When that happens, recovering the encrypted files becomes effectively impossible—even if a victim wanted to comply with the ransom demand.
That causes those variants to behave more like destructive wipers disguised as ransomware.
.NET Variant
The .NET version uses:
AES-256-CBC
and sends its generated encryption key to command-and-control infrastructure.
Kaspersky also identified capabilities for:
- Privilege escalation
- Disabling Windows recovery
- Extracting Microsoft Outlook credentials
- Deleting backup-related files
- Sending stolen information to C2 infrastructure
- Self-deletion
C++ Variant
The C++ version contains a broader collection of defense-evasion and system-disruption functionality.
Reported capabilities include:
- Scheduled-task persistence
- RunOnce persistence
- Clearing system logs
- Deleting PowerShell command history
- Disabling logging
- AMSI bypass
- ETW interference
- Microsoft Defender exclusions
- Disabling Task Manager
- Disabling Command Prompt
- Disrupting backup mechanisms
- Disabling Volume Shadow Copy Service
These capabilities are designed to reduce the victim's ability to detect the attack and recover after encryption.
Golang Variant
The Golang version primarily targets Linux and VMware ESXi.
It can:
- Establish persistence through
crontab - Disable SELinux
- Disable AppArmor
- Perform destructive operations
Kaspersky noted that the malware also contains Windows-oriented functionality that serves little purpose on Linux or ESXi. The researchers suggested this could indicate careless reuse or possibly AI-assisted development, but that explanation remains Kaspersky's assessment rather than a confirmed fact.
ClearWater and Nemo Wiper Also Reported
Kaspersky also associated collaborative Hacking Cat operations with additional destructive malware.
One is ClearWater, ransomware reportedly distributed through a ransomware-as-a-service model to pro-Ukrainian hacktivist groups.
Another is Nemo Wiper.
Nemo is designed for destruction rather than conventional financial extortion.
The malware overwrites victim files using random data and then consumes remaining free disk space using files with random alphanumeric names and a:
.lock
extension.
Such activity can significantly complicate recovery if organizations lack isolated and verified backups.
Hacking Cat Disputes Part of Kaspersky's Attribution
The attribution surrounding Hacking Cat requires an important qualification.
After Kaspersky's findings were published, Hacking Cat reportedly acknowledged ownership of some tools but denied that the ransomware/locker families attributed to it belonged to the group.
The group accused Kaspersky of combining tools belonging to unrelated actors.
Kaspersky, meanwhile, noted that multiple hacktivist groups appear to use some of the same custom tools and multi-stage infection chains.
Researchers suggested that a shared developer—or small development group—could potentially create and maintain malware subsequently used by multiple hacktivist organizations.
Therefore, the ransomware and wiper relationships should be presented as Kaspersky's attribution, rather than as independently established ownership.
Toy Ghouls Develops Its Own Backdoor
The third threat cluster is Toy Ghouls, also tracked as:
Bearlyfy
Laboo.boo
Feral Wolf
The financially motivated group has been active since 2025.
Earlier Toy Ghouls operations relied on leaked Babuk and LockBit ransomware builders.
The group subsequently developed its own ransomware, known as GenieLocker, and has now expanded its toolkit with a custom backdoor.
Kaspersky first detected the new backdoor in July 2026.
Bird Agent Uses MQTT and Matrix for C2
The custom backdoor, referred to as Bird Agent, exists in two identified versions:
| Variant | C2 Channel |
|---|---|
mqtt-bird-agent 0.1.0 |
HiveMQ MQTT broker |
matrix-bird-agent 0.1.0 |
Element / Matrix messaging |
Instead of relying solely on conventional attacker-controlled web servers, Toy Ghouls uses legitimate communication technologies for command-and-control.
Using common messaging and IoT-style communication protocols can make malicious traffic harder to distinguish from legitimate network activity.
WinRM Used to Deploy Bird Agent
Toy Ghouls uses Windows Remote Management (WinRM) to distribute its backdoor and configuration files to compromised systems.
The group has also used open-source tools including:
Evil-WinRM
and
WinRM-fs
for this purpose.
Once installed, Bird Agent can run interactively or establish persistence as a Windows service.
The malware searches for:
config.toml
which contains configuration required for command-and-control communication.
Configuration Bound to Individual Machines
Bird Agent partially encrypts its configuration using a key derived from the Windows:
MachineGuid
Registry value.
This effectively binds the configuration to a particular compromised computer.
If the malware cannot successfully decrypt its configuration during subsequent execution, it terminates.
The MQTT version stores information required to communicate with the HiveMQ broker, while the Matrix version contains information required to access an Element room.
Commands Executed Through PowerShell or Windows CLI
Once command-and-control communication is established, Bird Agent sends system information and retrieves attacker instructions.
The MQTT variant can execute commands using PowerShell with parameters including:
-NonInteractive -NoProfile -Command
The results are then returned to the attacker.
The Element variant performs similar operations but executes received instructions through the Windows command-line environment.
The use of MQTT and Matrix demonstrates how attackers can increasingly abuse legitimate communication services and protocols for command-and-control operations.
What Security Teams Should Monitor
Organizations concerned about these techniques should monitor multiple stages of the attack chain rather than relying exclusively on malware signatures.
Useful detection areas include:
- VPN authentication from unusual infrastructure
- Valid accounts connecting from unexpected locations
- Exchange exploitation attempts
- Suspicious Exchange worker-process behavior
- Unexpected
VIEWSTATEactivity - Web shells and in-memory Exchange payloads
- RDP tunneling
- Microsoft development tunnels used unexpectedly
rdp2tcp- DCSync behavior
- Unexpected Active Directory replication requests
- New local administrator accounts
- Unauthorized Remote Desktop Users membership
- Suspicious WinRM activity
- Evil-WinRM usage
- New Windows services
- Unexpected PowerShell execution
- HiveMQ/MQTT traffic from enterprise endpoints
- Matrix/Element communications from unusual server processes
- Attempts to disable Defender, AMSI or ETW
- Backup and VSS disruption
- Unexpected encryption across Windows, Linux or ESXi infrastructure
Identity telemetry is particularly important because NightEagle frequently begins with valid compromised credentials rather than an obvious malware payload.
Defensive Priorities
Organizations can reduce exposure by strengthening several areas simultaneously:
- Require strong MFA for remote VPN access.
- Monitor successful authentication, not only failed logins.
- Patch internet-facing Microsoft Exchange servers rapidly.
- Restrict administrative access to Exchange infrastructure.
- Monitor privileged Active Directory replication operations.
- Protect domain-controller credentials.
- Segment critical server and virtualization networks.
- Restrict WinRM where it is unnecessary.
- Monitor RDP tunneling and unusual port forwarding.
- Maintain offline or immutable backups.
- Test ransomware recovery procedures.
- Monitor attempts to disable EDR and recovery services.
- Restrict unnecessary outbound MQTT and messaging traffic from servers.
- Hunt for persistence after any confirmed compromise.
For ransomware and wiper incidents, backups should be isolated from the production identity environment wherever practical. An attacker who obtains domain-level access may otherwise be able to destroy both production data and accessible backups.
Security Takeaway
The campaigns targeting Russian enterprises demonstrate three different approaches to enterprise compromise.
NightEagle focuses heavily on identity compromise, Exchange persistence, tunneling and Active Directory takeover.
Hacking Cat, according to Kaspersky's attribution, has moved toward remote-access malware, ransomware and destructive operations—although the group disputes ownership of some of the attributed ransomware tools.
Toy Ghouls is evolving from publicly available ransomware builders toward custom malware, including Bird Agent and unconventional command-and-control channels based on MQTT and Matrix.
Together, the activity illustrates how modern enterprise attacks increasingly combine:
Stolen Credentials + Vulnerable Infrastructure + Tunneling + Credential Theft + Custom Malware + Ransomware/Wipers
For defenders, the lesson is that preventing the initial intrusion is only one part of the challenge.
Organizations also need visibility capable of detecting what happens after attackers obtain legitimate credentials—particularly unusual VPN access, lateral movement, Active Directory replication abuse, tunneling, remote-management activity and attempts to disable recovery mechanisms.
Related reporting
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT Malware via ClickFix
Attackers abuse ChatGPT Custom GPTs and sponsored Google results to redirect victims to ClickFix pages that execute PowerShell and install remote access trojan malware.
Star Blizzard Targets 100+ Organizations With Fake Event Invites and CosmicPulse Backdoor
Russia-linked Star Blizzard targets more than 100 organizations using fake event invitations, the new RedFlick malware delivery technique and the CosmicPulse Windows backdoor.
101 Malicious npm Packages Secretly Add Developers to WhatsApp Groups
Researchers uncover 101 malicious npm packages in the PhantomSub campaign that abuse authenticated WhatsApp sessions to secretly add developers to attacker-controlled groups and channels.


