Skip to main content
The Wire
CyberNews by Zentrya One
CVE-2021-26855 and CVE-2026-42897 Malware

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware and Destructive Wipers

Kaspersky reports NightEagle, Hacking Cat and Toy Ghouls targeting Russian enterprises with VPN compromise, Exchange attacks, GhostContainer and Gorilla RAT backdoors, ransomware and destructive wipers.

Russian enterprises are facing attacks from three separate threat clusters using a combination of compromised VPN credentials, Microsoft Exchange exploitation, custom backdoors, ransomware and destructive wiper malware.

According to research published by Kaspersky, the activity involves groups tracked as NightEagle, Hacking Cat and Toy Ghouls.

While their motivations and techniques differ, the campaigns demonstrate a common focus on obtaining persistent access to enterprise networks, moving laterally through internal infrastructure and compromising high-value systems.

NightEagle has concentrated heavily on VPN access, Exchange servers and Active Directory compromise. Hacking Cat has been associated by Kaspersky with remote-access malware, ransomware and destructive attacks. Toy Ghouls, meanwhile, has expanded from publicly available ransomware builders toward its own ransomware and custom backdoor infrastructure.

Three Threat Clusters at a Glance

Threat Group Main Techniques Malware / Tools Primary Objective
NightEagle / APT-Q-95 Compromised VPN credentials, Exchange compromise, AD attacks, tunneling GhostContainer, Neo-reGeorg, rdp2tcp Persistence, credential theft and domain compromise
Hacking Cat Exchange exploitation, RAT deployment, encryption and destructive attacks Gorilla RAT, Monkey ransomware, reported use of ClearWater and Nemo Wiper Remote access, disruption and destruction
Toy Ghouls WinRM-based deployment, custom C2 and ransomware Bird Agent, GenieLocker Persistent access and financially motivated attacks

The three clusters should not be treated as a single threat operation.

NightEagle Targets VPNs, Exchange and Active Directory

The first group, NightEagle, also known as APT-Q-95, has been active since at least 2023.

Kaspersky reported that in many investigated incidents, attackers obtained initial access using compromised legitimate credentials for corporate VPN services.

The VPN connections originated from infrastructure including Cloudflare WARP-linked addresses in the Russian internet segment and European virtual infrastructure providers.

Using valid credentials can make intrusion detection more difficult because authentication may initially resemble legitimate remote access.

A simplified NightEagle intrusion can look like:

Compromised VPN credentials

↓

Corporate network access

↓

Microsoft Exchange targeted

↓

GhostContainer deployed

↓

Network tunnels established

↓

Active Directory attacked

↓

Credentials and password hashes obtained

↓

Domain infrastructure compromised

GhostContainer Provides Persistent Exchange Access

A major component of NightEagle's toolkit is GhostContainer, a modular backdoor previously associated with attacks against organizations in Asia.

GhostContainer is designed to operate on compromised Microsoft Exchange servers and provides capabilities including:

  • Arbitrary code execution
  • File operations
  • Additional module loading
  • Traffic tunneling
  • Network redirection
  • Persistent remote access

The malware attempts to blend into legitimate server activity by masquerading as a normal server component.

GhostContainer also incorporates components derived from publicly available projects, including Neo-reGeorg, code associated with exploitation of CVE-2020-0688, and the GhostWebShell class from ysoserial.

Kaspersky said the exact mechanism used in the observed incidents to initially place GhostContainer on Exchange servers remains unclear.

Researchers believe the process may involve obtaining cryptographic material from ASP.NET configuration and manipulating the VIEWSTATE mechanism to trigger in-memory execution.

NightEagle Uses Tunnels for Lateral Movement

Once inside an organization, NightEagle creates network tunnels to reach internal systems.

Researchers observed the attackers using Microsoft development tunnels and the open-source rdp2tcp utility to redirect traffic associated with Remote Desktop Protocol.

These tunnels can allow attackers to interact with internal infrastructure through systems they have already compromised.

The group has also exploited weaknesses in Active Directory environments as part of privilege escalation and lateral movement.

One vulnerability associated with the activity is:

CVE-2019-0708 — BlueKeep

NightEagle reportedly used exploitation activity to create local accounts and add those accounts to the:

Administrators

and

Remote Desktop Users

groups.

DCSync Used Against Active Directory

NightEagle has also attempted DCSync attacks.

DCSync abuses Active Directory replication functionality to request credential information in a way that imitates a domain controller.

If an attacker obtains sufficient privileges, the technique can expose sensitive authentication material, including password hashes associated with domain accounts.

NightEagle's broader objective appears to involve establishing long-term access through:

Password hashes
Kerberos authentication
Persistent tunnels
Domain-controller access

The ultimate result can be extensive control over an organization's Active Directory infrastructure.

Hacking Cat Shifts Toward Destructive Operations

The second cluster highlighted by Kaspersky is Hacking Cat, which the company describes as a pro-Ukrainian hacktivist group active since February 2024.

Earlier activity associated with the group included website defacement and data breaches.

Kaspersky says more recent operations have shifted toward encryption and destructive attacks.

The group has also been reported collaborating with other hacktivist organizations, including:

  • Cyber Anarchy Squad
  • Ukrainian Cyber Alliance

These overlaps make attribution more difficult because tools may be shared between multiple groups.

Exchange Vulnerabilities Used to Deliver Gorilla RAT

Kaspersky associated Hacking Cat operations with exploitation of Microsoft Exchange vulnerabilities including:

CVE-2021-26855

and

CVE-2026-42897

to deploy a Go-based remote-access trojan called Gorilla RAT.

After execution, Gorilla RAT connects to attacker-controlled infrastructure and registers the infected machine.

Operators can then issue commands allowing the malware to:

  • Execute arbitrary commands
  • Enumerate processes
  • Gather system information
  • Upload files
  • Download files
  • Create TCP tunnels
  • Close existing tunnels

Its tunneling capabilities can also provide attackers with access to other systems located deeper inside the compromised network.

Monkey Ransomware Targets Windows, Linux and ESXi

Kaspersky also linked Hacking Cat with a ransomware family called Monkey.

Researchers identified multiple implementations written in:

  • Rust
  • .NET
  • C++
  • Golang

The variants target a combination of Windows, Linux and VMware ESXi environments.

This cross-platform capability is important because compromising virtualization infrastructure can affect numerous workloads simultaneously.

Rust Variant

The Rust implementation generates a 32-byte encryption key and encrypts files using:

ChaCha20-Poly1305

Some samples reportedly fail to preserve the encryption key.

When that happens, recovering the encrypted files becomes effectively impossible—even if a victim wanted to comply with the ransom demand.

That causes those variants to behave more like destructive wipers disguised as ransomware.

.NET Variant

The .NET version uses:

AES-256-CBC

and sends its generated encryption key to command-and-control infrastructure.

Kaspersky also identified capabilities for:

  • Privilege escalation
  • Disabling Windows recovery
  • Extracting Microsoft Outlook credentials
  • Deleting backup-related files
  • Sending stolen information to C2 infrastructure
  • Self-deletion

C++ Variant

The C++ version contains a broader collection of defense-evasion and system-disruption functionality.

Reported capabilities include:

  • Scheduled-task persistence
  • RunOnce persistence
  • Clearing system logs
  • Deleting PowerShell command history
  • Disabling logging
  • AMSI bypass
  • ETW interference
  • Microsoft Defender exclusions
  • Disabling Task Manager
  • Disabling Command Prompt
  • Disrupting backup mechanisms
  • Disabling Volume Shadow Copy Service

These capabilities are designed to reduce the victim's ability to detect the attack and recover after encryption.

Golang Variant

The Golang version primarily targets Linux and VMware ESXi.

It can:

  • Establish persistence through crontab
  • Disable SELinux
  • Disable AppArmor
  • Perform destructive operations

Kaspersky noted that the malware also contains Windows-oriented functionality that serves little purpose on Linux or ESXi. The researchers suggested this could indicate careless reuse or possibly AI-assisted development, but that explanation remains Kaspersky's assessment rather than a confirmed fact.

ClearWater and Nemo Wiper Also Reported

Kaspersky also associated collaborative Hacking Cat operations with additional destructive malware.

One is ClearWater, ransomware reportedly distributed through a ransomware-as-a-service model to pro-Ukrainian hacktivist groups.

Another is Nemo Wiper.

Nemo is designed for destruction rather than conventional financial extortion.

The malware overwrites victim files using random data and then consumes remaining free disk space using files with random alphanumeric names and a:

.lock

extension.

Such activity can significantly complicate recovery if organizations lack isolated and verified backups.

Hacking Cat Disputes Part of Kaspersky's Attribution

The attribution surrounding Hacking Cat requires an important qualification.

After Kaspersky's findings were published, Hacking Cat reportedly acknowledged ownership of some tools but denied that the ransomware/locker families attributed to it belonged to the group.

The group accused Kaspersky of combining tools belonging to unrelated actors.

Kaspersky, meanwhile, noted that multiple hacktivist groups appear to use some of the same custom tools and multi-stage infection chains.

Researchers suggested that a shared developer—or small development group—could potentially create and maintain malware subsequently used by multiple hacktivist organizations.

Therefore, the ransomware and wiper relationships should be presented as Kaspersky's attribution, rather than as independently established ownership.

Toy Ghouls Develops Its Own Backdoor

The third threat cluster is Toy Ghouls, also tracked as:

Bearlyfy

Laboo.boo

Feral Wolf

The financially motivated group has been active since 2025.

Earlier Toy Ghouls operations relied on leaked Babuk and LockBit ransomware builders.

The group subsequently developed its own ransomware, known as GenieLocker, and has now expanded its toolkit with a custom backdoor.

Kaspersky first detected the new backdoor in July 2026.

Bird Agent Uses MQTT and Matrix for C2

The custom backdoor, referred to as Bird Agent, exists in two identified versions:

Variant C2 Channel
mqtt-bird-agent 0.1.0 HiveMQ MQTT broker
matrix-bird-agent 0.1.0 Element / Matrix messaging

Instead of relying solely on conventional attacker-controlled web servers, Toy Ghouls uses legitimate communication technologies for command-and-control.

Using common messaging and IoT-style communication protocols can make malicious traffic harder to distinguish from legitimate network activity.

WinRM Used to Deploy Bird Agent

Toy Ghouls uses Windows Remote Management (WinRM) to distribute its backdoor and configuration files to compromised systems.

The group has also used open-source tools including:

Evil-WinRM

and

WinRM-fs

for this purpose.

Once installed, Bird Agent can run interactively or establish persistence as a Windows service.

The malware searches for:

config.toml

which contains configuration required for command-and-control communication.

Configuration Bound to Individual Machines

Bird Agent partially encrypts its configuration using a key derived from the Windows:

MachineGuid

Registry value.

This effectively binds the configuration to a particular compromised computer.

If the malware cannot successfully decrypt its configuration during subsequent execution, it terminates.

The MQTT version stores information required to communicate with the HiveMQ broker, while the Matrix version contains information required to access an Element room.

Commands Executed Through PowerShell or Windows CLI

Once command-and-control communication is established, Bird Agent sends system information and retrieves attacker instructions.

The MQTT variant can execute commands using PowerShell with parameters including:

-NonInteractive -NoProfile -Command

The results are then returned to the attacker.

The Element variant performs similar operations but executes received instructions through the Windows command-line environment.

The use of MQTT and Matrix demonstrates how attackers can increasingly abuse legitimate communication services and protocols for command-and-control operations.

What Security Teams Should Monitor

Organizations concerned about these techniques should monitor multiple stages of the attack chain rather than relying exclusively on malware signatures.

Useful detection areas include:

  • VPN authentication from unusual infrastructure
  • Valid accounts connecting from unexpected locations
  • Exchange exploitation attempts
  • Suspicious Exchange worker-process behavior
  • Unexpected VIEWSTATE activity
  • Web shells and in-memory Exchange payloads
  • RDP tunneling
  • Microsoft development tunnels used unexpectedly
  • rdp2tcp
  • DCSync behavior
  • Unexpected Active Directory replication requests
  • New local administrator accounts
  • Unauthorized Remote Desktop Users membership
  • Suspicious WinRM activity
  • Evil-WinRM usage
  • New Windows services
  • Unexpected PowerShell execution
  • HiveMQ/MQTT traffic from enterprise endpoints
  • Matrix/Element communications from unusual server processes
  • Attempts to disable Defender, AMSI or ETW
  • Backup and VSS disruption
  • Unexpected encryption across Windows, Linux or ESXi infrastructure

Identity telemetry is particularly important because NightEagle frequently begins with valid compromised credentials rather than an obvious malware payload.

Defensive Priorities

Organizations can reduce exposure by strengthening several areas simultaneously:

  • Require strong MFA for remote VPN access.
  • Monitor successful authentication, not only failed logins.
  • Patch internet-facing Microsoft Exchange servers rapidly.
  • Restrict administrative access to Exchange infrastructure.
  • Monitor privileged Active Directory replication operations.
  • Protect domain-controller credentials.
  • Segment critical server and virtualization networks.
  • Restrict WinRM where it is unnecessary.
  • Monitor RDP tunneling and unusual port forwarding.
  • Maintain offline or immutable backups.
  • Test ransomware recovery procedures.
  • Monitor attempts to disable EDR and recovery services.
  • Restrict unnecessary outbound MQTT and messaging traffic from servers.
  • Hunt for persistence after any confirmed compromise.

For ransomware and wiper incidents, backups should be isolated from the production identity environment wherever practical. An attacker who obtains domain-level access may otherwise be able to destroy both production data and accessible backups.

Security Takeaway

The campaigns targeting Russian enterprises demonstrate three different approaches to enterprise compromise.

NightEagle focuses heavily on identity compromise, Exchange persistence, tunneling and Active Directory takeover.

Hacking Cat, according to Kaspersky's attribution, has moved toward remote-access malware, ransomware and destructive operations—although the group disputes ownership of some of the attributed ransomware tools.

Toy Ghouls is evolving from publicly available ransomware builders toward custom malware, including Bird Agent and unconventional command-and-control channels based on MQTT and Matrix.

Together, the activity illustrates how modern enterprise attacks increasingly combine:

Stolen Credentials + Vulnerable Infrastructure + Tunneling + Credential Theft + Custom Malware + Ransomware/Wipers

For defenders, the lesson is that preventing the initial intrusion is only one part of the challenge.

Organizations also need visibility capable of detecting what happens after attackers obtain legitimate credentials—particularly unusual VPN access, lateral movement, Active Directory replication abuse, tunneling, remote-management activity and attempts to disable recovery mechanisms.

Filed by Zentrya One Desk · CyberNews desk  ·  Follow Zentrya One on LinkedIn

Related reporting

The Daily Brief

Stay informed. Stay prepared. Stay one step ahead.

One brief each morning: the advisories that matter, the noise removed.

Double opt-in. One-click unsubscribe in every email. We never sell addresses.