Three Cybercriminal Groups Target Russian Enterprises
Kaspersky identifies NightEagle, Hacking Cat, and Toy Ghouls deploying backdoors, ransomware, and wipers against Russian businesses. NightEagle shows new persistence and lateral movement tactics.
TL;DR
- Three threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are targeting Russian enterprises.
- NightEagle has been active since at least 2023 and uses updated techniques for persistence.
- Attacks involve backdoors, ransomware, and destructive wiper malware.
- Kaspersky disclosed the findings based on observed cyber operations.
- Organizations should review network logs and endpoint detections for signs of compromise.
Cybersecurity firm Kaspersky has uncovered a surge in targeted attacks against Russian enterprises by three distinct threat actors. These groups—tracked as NightEagle, Hacking Cat, and Toy Ghouls—are leveraging a mix of backdoors, ransomware, and data-wiping malware to infiltrate and disrupt business operations.
Among the most notable is NightEagle, also known as APT-Q-95, which has been active since at least 2023. This group is evolving its approach with new methods for maintaining access and moving laterally within compromised networks, raising concerns about persistent and stealthy intrusions.
Threat Actor Tactics and Tools
- NightEagle employs novel persistence mechanisms to maintain long-term access to victim environments.
- Hacking Cat and Toy Ghouls favor ransomware and wiper payloads to cause immediate damage and financial impact.
- All three groups demonstrate increasing sophistication in evading detection and exploiting enterprise network weaknesses.
Defensive Recommendations
- Organizations should monitor for unusual credential usage and unauthorized lateral movement.
- Endpoint detection and response tools can help identify early signs of these threat actors' toolsets.
- Regular backups, network segmentation, and privileged access reviews are critical mitigation steps.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.