hacker-news · Crawled Sep 17, 2026

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

5 IoCs 2 Actors
Read original article ↗

AI Summary

Three distinct threat groups—NightEagle, Hacking Cat, and Toy Ghouls—are targeting Russian enterprises using backdoors, ransomware, and wipers. NightEagle exploits vulnerabilities like CVE-2019-0708 and CVE-2020-0688 to deploy the GhostContainer backdoor on Microsoft Exchange servers, enabling code execution and lateral movement. Hacking Cat, a pro-Ukrainian hacktivist group, uses Gorilla RAT and multiple variants of Monkey ransomware written in different languages, along with wiper malware Nemo Wiper, often in collaboration with other groups. Toy Ghouls has shifted to custom tools, deploying a new backdoor called Bird Agent that uses HiveMQ MQTT or Element (Matrix) for C2 communication, delivered via WinRM using tools like Evil-WinRM.

AI-extracted · verify before operational use

Extracted Entities 2 found

Indicators of Compromise 5 extracted

Type Value Detail
Domain api[.]ipify[.]org Details →
Domain ipapi[.]co Details →
Filename config.toml Details →
GitHub Repo ysoserial Details →
GitHub Repo Neo-reGeorg Details →

MITRE ATT&CK TTPs 28 techniques