CVE Tools

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

The Hacker NewsBy The Hacker News

Reported exploitedMicrosoft Exchange ServerNightEagle

Our summary

Kaspersky reports that NightEagle (APT-Q-95), Hacking Cat, and Toy Ghouls have targeted Russian enterprises with backdoors, ransomware, and destructive malware. NightEagle compromised Microsoft Exchange Server and exploited CVE-2019-0708 for lateral movement, while Hacking Cat abused Microsoft Exchange vulnerabilities CVE-2021-26855 and CVE-2026-42897 to deploy Gorilla RAT and Monkey ransomware. Toy Ghouls used WinRM to install Bird Agent backdoors that use MQTT or Matrix-based Element communications, increasing the risk of persistent access across affected networks.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store