Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
AI Summary
Three distinct threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are targeting Russian enterprises using backdoors, ransomware, and wipers. NightEagle exploits vulnerabilities like CVE-2019-0708 and CVE-2020-0688 to deploy the GhostContainer backdoor on Microsoft Exchange servers, enabling code execution and lateral movement. Hacking Cat, a pro-Ukrainian hacktivist group, uses Gorilla RAT and multiple variants of Monkey ransomware written in different languages, along with wiper malware Nemo Wiper, often in collaboration with other groups. Toy Ghouls has shifted to custom tools, deploying a new backdoor called Bird Agent that uses HiveMQ MQTT or Element (Matrix) for C2 communication, delivered via WinRM using tools like Evil-WinRM.
AI-extracted · verify before operational use