The latest research into cyberattacks targeting Russian enterprises provides an important illustration of how modern threat actors are combining credential compromise, legitimate administrative tools, sophisticated backdoors, ransomware and destructive malware to achieve different operational objectives. The three activity clusters identified by Kaspersky, NightEagle, Hacking Cat and Toy Ghouls, demonstrate distinct approaches to enterprise compromise, ranging from persistent espionage and Active Directory infiltration to ransomware deployment and the development of custom command-and-control infrastructure. Although the groups differ in their capabilities, techniques and reported motivations, their activities reveal a common security challenge: organisations can no longer assume that traffic originating from authenticated users, trusted applications or familiar communication protocols is necessarily legitimate. Attackers increasingly exploit the very tools and relationships that enterprises rely upon for routine operations, creating intrusions that can appear ordinary until the consequences become visible. 

NightEagle's activities are particularly instructive because the group reportedly gained initial access to corporate environments primarily through compromised valid VPN credentials. Rather than immediately exploiting an unknown vulnerability or deploying an obviously malicious executable, the attackers used existing remote-access infrastructure to enter networks under identities that the organisation already recognised. The observed VPN connections originated from infrastructure associated with Cloudflare WARP tunnels and European virtual infrastructure providers, demonstrating how legitimate connectivity services can be incorporated into malicious operations. This approach highlights a fundamental limitation of traditional perimeter security because a firewall or VPN gateway may correctly authenticate the supplied credentials while remaining unaware that the person using them is an attacker. Strong authentication remains essential, but organisations also need to evaluate device identity, location, session behaviour and the resources accessed after a connection is established.

Once inside the environment, NightEagle used GhostContainer, a modular backdoor associated with attacks against Microsoft Exchange servers. The malware can execute arbitrary code, manipulate files, load additional modules and redirect network traffic, providing a flexible foundation for persistence and further intrusion. Its ability to masquerade as an ordinary server component makes the attack particularly concerning because conventional monitoring may classify the process as part of legitimate Exchange operations. Researchers have described a suspected delivery mechanism involving extracted ASP.NET cryptographic keys and manipulation of the VIEWSTATE parameter to launch the payload in memory, although the precise initial deployment method has not been conclusively established. The broader lesson is that enterprise applications holding sensitive information and privileged integration credentials need continuous monitoring of their internal behaviour, not merely protection against external connection attempts.

The subsequent lateral-movement activity illustrates how an initial compromise can evolve into a much broader identity-security incident. NightEagle reportedly deployed tunnelling utilities to redirect RDP traffic through established connections, exploited weaknesses in Active Directory and attempted to obtain elevated privileges. The group's objectives included collecting password hashes, acquiring long-lived Kerberos tickets and gaining access to domain controllers, demonstrating that compromising the identity infrastructure was a central part of its strategy. This progression matters because Active Directory is not simply another application; it frequently determines which users, computers and services can access critical enterprise resources. Once an attacker compromises domain-level identity controls, previously established trust relationships can become mechanisms for moving across the network and maintaining access.

The use of long-lived Kerberos authentication material is especially significant because it illustrates why changing a compromised password may not always be sufficient to terminate an intrusion. Attackers who obtain reusable tickets, password hashes or other authentication material may retain access through mechanisms that do not immediately require the original password. Organisations therefore need comprehensive identity incident-response procedures that include investigation of privileged authentication, credential rotation, session invalidation and assessment of possible domain-controller compromise. Monitoring should also identify unusual Kerberos activity, unexpected administrative account creation and authentication patterns inconsistent with the normal behaviour of users and systems.

The second threat cluster, Hacking Cat, demonstrates a different progression in which politically motivated hacktivist activity has reportedly expanded from website defacement and data breaches into ransomware and destructive attacks. Kaspersky associates the group with activity targeting Microsoft Exchange vulnerabilities to deploy Gorilla RAT, a Go-based remote-access trojan capable of executing commands, collecting system information, transferring files and establishing network tunnels. Once attackers gain a foothold through an exposed application, these capabilities can support reconnaissance, lateral movement and additional payload deployment. The transition from website-focused disruption toward enterprise ransomware and destructive malware illustrates how threat groups can change tactics and operational capabilities over time, making historical assumptions about their behaviour an unreliable basis for defensive planning.

The Monkey ransomware family associated by researchers with this activity introduces one of the most important findings in the report because several variants extend beyond conventional ransomware functionality. Samples written in Rust, .NET, C++ and Golang target Windows, Linux and VMware ESXi environments, demonstrating an effort to affect multiple operating systems and infrastructure layers. Some versions attempt to terminate running processes, disable recovery mechanisms, destroy backups, interfere with security controls and encrypt files. Other variants reportedly fail to preserve the encryption key or provide a meaningful recovery mechanism, effectively functioning as destructive wipers despite displaying ransom notes. This distinction is critical because ransomware generally implies the possibility, however uncertain, of recovering encrypted information through a decryption key, while destructive malware may make recovery technically impossible regardless of whether a ransom is paid.

The destructive behaviour changes how organisations should evaluate the potential consequences of an attack. When malware deletes backup files, disables recovery services and destroys encryption keys, the incident can no longer be treated solely as an extortion attempt. Business continuity becomes the primary concern because the attacker may be attempting to eliminate the organisation's ability to restore operations. This reinforces the importance of maintaining offline or immutable backups, segregating backup administration from production identities and regularly testing restoration procedures. A backup system that remains connected to production with unrestricted administrative access may be compromised at exactly the moment it becomes most important.

The inclusion of VMware ESXi and Linux among the targeted platforms also demonstrates why ransomware defence cannot remain focused primarily on Windows workstations. Modern enterprise infrastructure frequently depends on virtualisation platforms that host hundreds of business-critical applications, including identity services, databases, customer systems and internal communication platforms. An attack against the hypervisor layer can potentially affect numerous virtual machines simultaneously, creating a much larger operational impact than compromising individual endpoints. Organisations should therefore treat virtualisation management interfaces, hypervisors and backup infrastructure as highly privileged assets requiring strong segmentation, restricted administrative access, rapid vulnerability remediation and independent monitoring.

The malware's attempts to disable security controls are equally revealing. Researchers described variants capable of interfering with Microsoft Defender, AMSI, Event Tracing for Windows, command histories and system logs, while Linux-oriented variants attempted to disable SELinux and AppArmor. These actions demonstrate that attackers are not simply trying to avoid initial detection but are actively weakening the defensive environment before executing their final payload. Security teams should treat unexpected changes to security-service configurations, logging mechanisms and backup settings as potential indicators of an intrusion in progress. Monitoring these preparatory activities may provide valuable opportunities to intervene before destructive malware is activated.

Attribution within the Hacking Cat activity requires particular care. Kaspersky reports collaboration between the group and other pro-Ukrainian hacktivist organisations, including operations involving ClearWater ransomware and Nemo Wiper, but Hacking Cat subsequently disputed parts of the attribution and denied ownership of the ransomware tools identified in the research. Shared malware, overlapping infrastructure and collaboration between groups can make it difficult to determine which actor developed or deployed a particular tool. The defensive lesson is that organisations should prioritise verified technical behaviour, exploitation methods and indicators of compromise rather than relying exclusively on threat-actor labels, particularly when attribution remains contested.

The third group, Toy Ghouls, provides a particularly interesting example of attackers moving from publicly available ransomware builders toward custom malware designed for longer-term access and evasion. Researchers observed the group's Bird Agent backdoor in two variants, one communicating through the HiveMQ MQTT messaging infrastructure and another using Element, a Matrix-based messaging application. These communication methods demonstrate how attackers increasingly exploit legitimate platforms and protocols to transport commands and retrieve information. Rather than maintaining an obvious direct connection to a conventional malicious server, the malware can communicate through messaging infrastructure that may already be permitted in certain enterprise environments.

MQTT is especially relevant because it was designed to provide lightweight, reliable communication between connected devices and applications. Its publish-and-subscribe architecture allows systems to exchange information through a messaging broker, making it useful for legitimate IoT and industrial deployments. However, the same characteristics can support malware command-and-control operations by separating the compromised endpoint from the attacker and allowing instructions to pass through an intermediary service. The security challenge is therefore not that MQTT itself is malicious, but that its legitimacy can make malicious communication less obvious when organisations lack visibility into which systems should be using the protocol and which external brokers they are permitted to contact.

The Matrix-based variant introduces a similar concern because encrypted messaging platforms can become channels for transmitting attacker instructions. A security system that identifies the traffic as communication with a legitimate messaging service may not automatically recognise that the application is being used to control compromised infrastructure. This reinforces the importance of application-aware monitoring and contextual analysis. A workstation unexpectedly communicating with a messaging service may be legitimate, but the same activity becomes considerably more suspicious when it follows an unusual software installation, accompanies hidden command execution or originates from a server that has no business requirement for such communication.

Toy Ghouls also reportedly used Windows Remote Management to deploy the backdoor and its configuration files, relying on open-source administrative utilities. This is another example of attackers abusing legitimate management functionality instead of developing a completely independent execution mechanism. WinRM is widely used for remote administration, automation and system management, making it difficult to distinguish malicious usage from legitimate operations without considering the originating identity, source system, destination and commands executed. Organisations should therefore establish clear policies defining which administrative workstations and accounts may use WinRM, which systems they may manage and what behaviour is expected during normal operations.

The backdoor's configuration handling adds another layer of sophistication because it derives encryption material from the compromised system's Windows MachineGuid, binding the configuration to that particular machine. This can complicate analysis when security researchers attempt to reproduce malware behaviour in a different environment, because the configuration may no longer decrypt correctly outside the original system. Such techniques illustrate how malware developers increasingly incorporate anti-analysis and environment-specific behaviour to make investigations more difficult. Defenders therefore need to collect relevant configuration artifacts and system context during incident response rather than relying exclusively on examining the executable in isolation.

Across all three clusters, one recurring theme is the systematic exploitation of legitimate enterprise functionality. VPN credentials provide initial access, Microsoft Exchange becomes a persistence platform, Active Directory becomes a target for privilege escalation, RDP and WinRM support lateral movement, and MQTT or messaging services provide command-and-control channels. None of these technologies is inherently malicious, but each can become dangerous when its legitimate capabilities are controlled by an attacker. Security architecture must therefore evaluate the context in which a tool is being used rather than relying exclusively on whether the software is signed, the credentials are valid or the network protocol is approved.

This is precisely why network segmentation and least-privilege access remain essential. A compromised VPN account should not automatically provide broad connectivity to internal servers, an Exchange server should not possess unrestricted access to identity infrastructure and an administrative utility should not be usable from arbitrary workstations. Organisations should map legitimate communication paths, enforce restrictions between security zones and ensure that privileged operations originate from dedicated management environments. These controls may not prevent every initial compromise, but they can significantly restrict the attacker's ability to transform one compromised account or application into control over the entire enterprise.

Continuous threat detection must also combine endpoint, identity and network telemetry. An individual event such as a successful VPN login, an RDP connection or an outbound MQTT session may appear ordinary when examined separately, but the sequence becomes much more meaningful when those activities are correlated with unusual privilege escalation, credential access, unexpected process execution and modifications to security controls. Detection systems should therefore establish behavioural baselines for important assets and identify deviations based on the relationship between identities, applications, destinations and actions. The objective is to recognise the developing intrusion before attackers establish persistence, obtain domain-level credentials or deploy destructive payloads.

The broader cybersecurity lesson from these campaigns is that the boundary between espionage, ransomware and destructive operations is increasingly difficult to define solely by the malware used. A backdoor may support long-term intelligence collection, the same access can facilitate credential theft and lateral movement, and ransomware may be deliberately designed without a practical recovery mechanism. Organisations therefore need incident-response and business-continuity plans that account for multiple possible outcomes rather than assuming that every ransomware incident is fundamentally a financial negotiation or every backdoor is intended only for information theft.

Ultimately, the activities attributed to NightEagle, Hacking Cat and Toy Ghouls demonstrate that modern enterprise compromise is rarely the result of one isolated vulnerability or one malicious executable. Attackers combine stolen identities, exposed applications, administrative tools, custom malware and legitimate communication platforms into multi-stage operations that exploit weaknesses across the entire security architecture. The defensive response must be equally integrated, combining strong identity protection, rapid vulnerability remediation, application-aware network security, endpoint behavioural monitoring, segmentation, privileged-access controls and independently protected backups. The central lesson is that trust should never be permanent merely because a connection originates from a recognised VPN, a command is executed through a legitimate management tool or traffic uses a familiar protocol. Effective cybersecurity depends on continuously understanding who is performing an action, which system is involved, what information or resources are being accessed and whether the behaviour is consistent with the organisation's legitimate operational requirements.


Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

Source: Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers via The Hacker News — published 16 Sep 2026.