As reported by The Hacker News, enterprises in Russia have become the target of three distinct threat activity clusters: NightEagle, Hacking Cat, and Toy Ghouls, according to recent analyses from Kaspersky. These groups are employing a range of sophisticated techniques, from exploiting valid credentials to deploying custom backdoors and ransomware, indicating a significant rise in targeted cyber threats against Russian organizations.NightEagle, active since at least 2023, has been observed using compromised valid credentials to access corporate VPNs, often routed through Cloudflare WARP tunnels or European virtual infrastructure. The group deploys the GhostContainer backdoor, which grants extensive access to Microsoft Exchange Servers, and utilizes tunneling tools like Microsoft dev tunnels and rdp2tcp for lateral movement. They also exploit vulnerabilities such as CVE-2019-0708 (BlueKeep) and employ DCSync attacks to gain elevated privileges and compromise Active Directory infrastructure.Hacking Cat, a pro-Ukrainian hacktivist group, has shifted from defacements to encryption and destructive attacks. They weaponize Exchange server vulnerabilities to deploy the Gorilla RAT and various variants of the Monkey ransomware, written in multiple languages to target Windows, Linux, and VMware ESXi systems. Some Monkey ransomware variants function as wipers, while others steal credentials or disable recovery mechanisms. Hacking Cat has also collaborated with other groups to distribute ClearWater ransomware and Nemo Wiper malware.Toy Ghouls, a financially motivated group, has moved from using leaked ransomware builders to its custom GenieLocker ransomware and now to bespoke backdoors, dubbed Bird Agent. These backdoors use unconventional command-and-control channels like HiveMQ MQTT brokers and the Matrix-based Element messenger, indicating an effort to enhance sophistication and evade detection. The group utilizes tools like Evil-WinRM for delivery and aims to establish persistence and exfiltrate data.Source: The Hacker News
Threat Intelligence
Russian enterprises targeted by NightEagle, Hacking Cat and Toy Ghouls threat actors
(Adobe Stock)
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
