Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
Three distinct threat groups – NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls – are actively targeting Russian enterprises with a combination of sophisticated tools, including custom backdoors, ransomware, and wipers. NightEagle utilizes GhostContainer, a modular backdoor, and exploits Active Directory vulnerabilities to establish persistence and move laterally within networks. Hacking Cat, a pro-Ukrainian hacktivist group, leverages Gorilla RAT and Monkey ransomware, often in collaboration with other groups. Toy Ghouls has recently shifted to custom backdoors utilizing HiveMQ MQTT and the Element messenger app, demonstrating an effort to evade detection. These groups are employing unconventional communication channels and increasingly developing their own tools, indicating a growing sophistication in their operations.
Enterprises in Russia are facing a coordinated wave of cyberattacks from three distinct threat groups: NightEagle (aka APT-Q-95), Hacking Cat, and Toy Ghouls. These groups are leveraging a diverse arsenal of tools, including custom backdoors, ransomware, and wipers, to achieve their objectives.
NightEagle, active since 2023, employs the GhostContainer backdoor, a modular tool that grants operators complete access to Microsoft Exchange Servers and allows them to execute arbitrary code, perform file operations, and redirect traffic. The group utilizes compromised credentials to gain access to VPNs originating from Cloudflare WARP tunnels and European virtual infrastructure providers. NightEagle has been observed exploiting vulnerabilities in Active Directory, including BlueKeep and DCSync, to establish persistence and move laterally within internal networks, often using open-source tools like Evil-WinRM and WinRM-fs. They also exploit previously established tunnels to connect to internal infrastructure systems.
The second group, Hacking Cat, a pro-Ukrainian hacktivist entity, has recently shifted its tactics, moving from website defacements and data breaches to encryption and destructive attacks. The group collaborates with other hacktivists, such as Cyber Anarchy Squad and the Ukrainian Cyber Alliance, complicating attribution. Hacking Cat utilizes Gorilla RAT and Monkey ransomware, often in partnership with these groups. They have also deployed a ClearWater ransomware strain under a RaaS model.
Finally, Toy Ghouls (aka Bearlyfy, Laboo.boo, and Feral Wolf) has moved away from using leaked Babuk and LockBit ransomware builders, now deploying custom GenieLocker ransomware and a bespoke backdoor. The group is actively targeting Russian organizations since 2025. The new Bird Agent backdoors utilize HiveMQ MQTT broker and the Matrix-based Element messenger app for C2 communication. These backdoors can run within an interactive command-line session or set up persistence as a Windows service, reading configuration files from the same directory or specifying a full path. The malware sends system information and issues HTTP GET requests to the HiveMQ broker to fetch commands from the C2 server, executing them via PowerShell in hidden mode and transmitting the results back to the server. The group relies on open-source tools such as Evil-WinRM and WinRM-fs to deliver the backdoors and their configuration files to compromised systems.
These groups are increasingly developing their own tools, suggesting a growing sophistication in their operations and an effort to evade detection for longer periods. The shift to custom communication channels demonstrates a proactive approach to staying ahead of security measures.
